Skip to main content

Researchers discover new class of Android malware that hides its tracks

android cloak dagger malware phone
ymgerman/123RF
A common permission in many apps downloaded from the Google Play Store could make it relatively easy for a malicious developer to gain complete control over your device. That’s according to researchers at the University of California and the Georgia Institute of Technology, who discovered the new type of attack and have already shared their findings with Google.

They’re calling it “Cloak and Dagger,” and it relies on the ability of apps to draw UI elements over the screen as a way of concealing from the user exactly what is being shown. In the example given, several prompts are displayed when a malicious app is opened. The user thinks they’re interacting with the app, but they’re actually enabling an accessibility service that can be used to log keystrokes, including passwords.

Recommended Videos

Then, the real magic happens. Here, the user is made to watch a video — all the while, in the background, the malware is flipping switches to grant itself a variety of other permissions, including the ability to read location, text messages, and storage.

Cloak & Dagger: Clickjacking + Silent God-mode App Install

Ironically, all apps downloaded through Google’s storefront can enable the two permissions necessary for the attack without the user’s knowledge. In other words, it’s on Google to detect the scheme before the app hits the Play Store. If it slips through, as some do from time to time, the only way the user could stop it is by digging into the apps menu and checking permissions granted.

Please enable Javascript to view this content

One of the most dangerous aspects of the Cloak and Dagger scheme is that researchers say it can be used to record your PIN code to discreetly unlock your device and perform actions — without ever turning the screen on.

According to the researchers, the latest version of Android, release 7.1.2, modifies the way permissions are handled in a way that makes it slightly harder to carry out an attack like this one. However, it doesn’t fully solve the issue.

Google has since responded to the news, stating to Engadget that it has updated Google Play Protect, its security software on most Android devices, to detect the presence of harmful apps that abuse these permissions. The company also reports that changes it made in Android O will “further strengthen” the platform against Cloak and Dagger attacks.

Adam Ismail
Former Digital Trends Contributor
Adam’s obsession with tech began at a young age, with a Sega Dreamcast – and he’s been hooked ever since. Previously…
This cool new Android tablet is hiding a very big secret
The Poco Pad tablet in different colors

If you know the Poco brand, it’s because of its brightly colored, reasonably priced, often gaming-focused smartphones. Now, the company has branched out into the world of Android tablets with the launch of the Poco Pad. The Poco Pad is a big-screen slate that, despite being only 7.5mm thick, hides a very big secret inside: a whopping 10,000mAh battery for those extended periods when you're away from the charger.

A battery capacity like this sets it apart from many other Android tablets. The Google Pixel Tablet’s 7,020mAh battery sounds positively small by comparison, and Poco pad's battery also improves on the Samsung Galaxy Tab S9’s 8,400mAh battery — and even the OnePlus Pad's 9.510mAh cell. To get a larger capacity battery in a tablet, you’ll need to look at the Samsung Galaxy Tab S9 FE Plus or the pricey Galaxy Tab S9 Ultra.

Read more
Android 15 might add a new way to charge your gadgets
The Android 15 logo on a smartphone.

Wireless charging has been a fringe feature for over a decade, despite Apple's push into the ecosystem with the iPhone X and its later adoption of MagSafe. It has been limited to flagship phones, save for a few exceptions, mostly due to the painfully slow charging speeds. But with Android 15, Google now seems to offer phone makers additional reasons to adopt wireless charging even without dedicated hardware.

Instead of relying on a dedicated charging coil, Android 15 could enable wireless charging on phones with Near Field Communications (or NFC) tech. Android Authority dug up instances from the source code of Android 15's first user beta, which arrived last week, that suggests the implementation.
Not new, but definitely noteworthy
Samsung Galaxy S23 FE Tushar Mehta / Digital Trends

Read more
A new Android 15 update just launched. Here’s everything that’s new
Android 15 logo on a Google Pixel 8.

Less than a month ago, Google formally announced Android 15 and released the first developer preview for the software update. Now, Google is rolling out Android 15 Developer Preview 2 — and with it — a few new features that weren't in Developer Preview 1.

So, what's new in this second developer preview? Here are the biggest things to keep an eye out for.
New satellite connectivity features

Read more