Hackers are using this trusted site to steal your data

A new report reveals a clever trick designed to bypass your phone's security.

0comments
Play Store updates
Imagine that you are surfing the internet when suddenly, out of nowhere, a pop-up window appears and tells you that your phone is infested with viruses. Well, obviously, the first thing that comes to mind is how to fix it. You click on the button, and then follow a few more steps that look exactly like the official Google Play system updates that come out every month. And then, voila! You have saved your phone. Or so you think. What if, in reality, you have just invited a digital thief into your living room?

A smart and devious trick that’s been hiding in plain sight


A new report has been issued by a group of researchers who have managed to track down a new and devious trick that has been targeting Android users via a platform that most people would trust: Hugging Face. For the uninitiated, Hugging Face is like the "hub" of AI and tech-related software and data, a place where tech enthusiasts and programmers go to share their genuine tech-related stuff. However, now hackers are using this reputable name to distribute their malware and malicious software.

Recommended For You

The malware in question is an app named TrustBastion, and it’s what’s known as "scareware," which scares people into thinking that their phone is in danger. Once it’s been installed, it then demands that the user "update" their software immediately.



Why this is a big deal for Android users


This is a big deal because it indicates that hackers are getting more and more sophisticated at what’s known as "social engineering." They are now using Hugging Face, so it looks like normal traffic and doesn’t arouse any suspicions.

As mentioned in the report, this is not a one-time effort by the hackers. They were also uploading new versions of this malware every 15 minutes to stay ahead of antivirus software. While the initial sources of this malware have been removed, this is simply a case of popping up again with different icons but with the same malicious code.

This is particularly frightening for non-techie folks because once this malware is installed, it asks for "Accessibility Services." While this is a feature meant for people with disabilities, it allows hackers to gain full access to see what you’re seeing on your screen, record all of your taps, and even steal your login credentials for apps like Alipay or WeChat.

How do you usually handle unexpected security alerts on your phone?


What you should know


To be honest with you, it is getting harder and harder to distinguish what is real and what is a scam these days. I think my best advice is to never trust a pop-up that tells you that your phone is infected while simply browsing a web page.

I would recommend only getting apps from the official Google Play Store. While nothing is ever 100% secure, I think this is a much safer approach than clicking a link from a "Phone Security" app that you have never even heard of. If you do get prompted for an update from a new app that looks like a legitimate update window for a new app, I think it is best to close that app and check your actual phone settings instead. Be careful and protect yourselves!


Try Noble Mobile for only $10

Get unlimited talk, text, & data on the T-Mobile 5G Network plus earn cash back for data you don’t use.
Buy at Noble Moblie
Google News Follow
Follow us on Google News

Recommended For You

COMMENTS (0)
FCC OKs Cingular\'s purchase of AT&T Wireless