cross-posted from: https://infosec.pub/post/53326082

A malware campaign dubbed 'Midnight Mimosa' has been discovered on low-cost Android smartphones that ship with malicious software embedded in their firmware, allowing attackers to silently install apps, perform ad fraud, and turn devices into residential proxies. [...]

you are viewing a single comment's thread
view the rest of the comments
[+] -13 points 11 hours ago (9 children)

So...kinda like what apple and google are doing too 😁

  • source
  • hideshow 9 child comments
  • [–] 32 points 10 hours ago (1 child)

    Not to shill for Apple or Google, but it's definitely important to draw a distinction between first party telemetry and straight up distributing malware. If we can't we honest in our framing then there is really no reason to take what we have to say seriously.

  • source
  • parent
  • hideshow 1 child comment
  • [–] 0 points 4 hours ago

    While I wasn't 100% serious, I wasn't just joking either.

    Sure there is a difference. But not a big one. Do you know what each android process actually does? And both can install any shit they want at any time. You can't even uninstall their store or apps.

    To me personally, the difference is slim. And malware is malware, the difference often is just billions of dollars and doing it more or less on the open.

  • source
  • parent
  • [–] 20 points 10 hours ago (1 child)

    No, because Apple and Google aren’t providing third parties access to the Internet through your devices.

  • source
  • parent
  • hideshow 1 child comment
  • [–] 1 point 4 hours ago

    Makes me feel so much safer with google or Apple 😁 They could though. All the tech for it is there and already installed. And you wouldn't even know if they did, because you don't own your own phone.

    Not that I wouldn't worry about an added layer of spy-shit though. The difference between that malware and the big malware it's installed on is just slim to me. I'm very security- and privacy-driven.

  • source
  • parent