{"id":6353,"date":"2019-06-17T12:33:55","date_gmt":"2019-06-17T17:33:55","guid":{"rendered":"http:\/\/allidm.com\/blog\/?p=6353"},"modified":"2019-07-07T09:44:51","modified_gmt":"2019-07-07T14:44:51","slug":"malware-sidesteps-google-permissions-policy-with-new-2fa-bypass-technique","status":"publish","type":"post","link":"https:\/\/allidm.com\/blog\/malware-sidesteps-google-permissions-policy-with-new-2fa-bypass-technique\/","title":{"rendered":"Malware sidesteps Google permissions policy with new 2FA bypass technique"},"content":{"rendered":"\n<p class=\"wp-block-paragraph\">When Google <a href=\"https:\/\/support.google.com\/googleplay\/android-developer\/answer\/9047303\" target=\"_blank\" rel=\"noreferrer noopener\">restricted the use<\/a>\n of SMS and Call Log permissions in Android apps in March 2019, one of \nthe positive effects was that credential-stealing apps lost the option \nto abuse these permissions for bypassing SMS-based two-factor \nauthentication (2FA) mechanisms.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">We have now discovered malicious apps capable of accessing one-time \npasswords (OTPs) in SMS 2FA messages without using SMS permissions, \ncircumventing Google\u2019s recent restrictions. As a bonus, this technique \nalso works to obtain OTPs from some email-based 2FA systems.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The apps impersonate the Turkish cryptocurrency exchange BtcTurk and  phish for login credentials to the service. Instead of intercepting SMS  messages to bypass 2FA protection on users\u2019 accounts and transactions,  these malicious apps take the OTP from notifications appearing on the  compromised device\u2019s display. Besides reading the 2FA notifications, the  apps can also dismiss them to prevent victims from noticing fraudulent  transactions happening.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Read more at &#8211; <a href=\"https:\/\/www.welivesecurity.com\/2019\/06\/17\/malware-google-permissions-2fa-bypass\/\" target=\"_blank\" rel=\"noreferrer noopener\" aria-label=\"Malware sidesteps Google permissions policy with new 2FA bypass technique (opens in a new tab)\">Malware sidesteps Google permissions policy with new 2FA bypass technique<\/a><\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><\/p>\n","protected":false},"excerpt":{"rendered":"<p>When Google restricted the use of SMS and Call Log permissions in Android apps in March 2019, one of the positive effects was that credential-stealing apps lost the option to abuse these permissions for bypassing SMS-based two-factor authentication (2FA) mechanisms. We have now discovered malicious apps capable of accessing one-time passwords (OTPs) in SMS 2FA [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"nf_dc_page":"","_jetpack_newsletter_access":"","_jetpack_dont_email_post_to_subs":false,"_jetpack_newsletter_tier_id":0,"_jetpack_memberships_contains_paywalled_content":false,"_jetpack_memberships_contains_paid_content":false,"footnotes":""},"categories":[1901,1900],"tags":[1160,1762],"class_list":["post-6353","post","type-post","status-publish","format-standard","hentry","category-identity-access-management","category-identity-manager","tag-2fa","tag-google"],"jetpack_featured_media_url":"","jetpack_shortlink":"https:\/\/wp.me\/p25vfy-1Et","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/allidm.com\/blog\/wp-json\/wp\/v2\/posts\/6353","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/allidm.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/allidm.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/allidm.com\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/allidm.com\/blog\/wp-json\/wp\/v2\/comments?post=6353"}],"version-history":[{"count":1,"href":"https:\/\/allidm.com\/blog\/wp-json\/wp\/v2\/posts\/6353\/revisions"}],"predecessor-version":[{"id":6354,"href":"https:\/\/allidm.com\/blog\/wp-json\/wp\/v2\/posts\/6353\/revisions\/6354"}],"wp:attachment":[{"href":"https:\/\/allidm.com\/blog\/wp-json\/wp\/v2\/media?parent=6353"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/allidm.com\/blog\/wp-json\/wp\/v2\/categories?post=6353"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/allidm.com\/blog\/wp-json\/wp\/v2\/tags?post=6353"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}