Catch up on stories from the past week (and beyond) at the Slashdot story archive

 



Forgot your password?
typodupeerror
×
Security Android Google Games

Infected Pokemon GO APK Carries Dangerous Android Backdoor 110

An anonymous reader writes: Users eager to get their hands on the new Nintendo mobile gaming app Pokemon GO, downloading unofficial copies of the game are opening themselves up to hackers who are circulating malicious versions of the Android APK. A remote access tool (RAT), known as DroidJack (or SandroRAT), has been added to some APK files, allowing third parties to gain full control over the users' mobile devices. Permissions granted to the dodgy app include; directly calling phone numbers, reading phone status' and identities, editing and reading text messages, sending SMS messages and recording audio.The problem is that Pokemon Go is not officially available in every region, and the Google PlayStore doesn't let people in an unsupported region download the app. Also, millions of smartphones and tablets don't support many Google Mobile Services (GMS). While we do not condone downloading installation files of Android apps and games from unofficial stores, APKMirror is one of the few places that we would suggest our readers to check as it has a very commendable track record.
This discussion has been archived. No new comments can be posted.

Infected Pokemon GO APK Carries Dangerous Android Backdoor

Comments Filter:
  • Can't wait to see kids running around the slums, whore houses, drug dens, and all kinds of shitholes looking for stupid pokemons.

    Kids + geocahing: what could possibly go wrong?
    • by lgw ( 121541 )

      Can't wait to see kids running around the slums, whore houses, drug dens, and all kinds of shitholes looking for stupid pokemons.

      I've been amused by considering the special Pokemon you can only catch in the sewers, or on the grounds of a nuclear power station, or on a military base, or in a burning building, or on a construction site. But sure, crack houses are fun too.

  • by Anonymous Coward on Monday July 11, 2016 @01:18PM (#52490527)

    That apk and his infected host file is dangerous

  • by _xeno_ ( 155264 ) on Monday July 11, 2016 @01:25PM (#52490577) Homepage Journal

    Also worth mentioning that if you log in to the game via your Google Account under iOS, Niantic gets "full access" to your Google account.

    Meaning that they can do things like:

    1. Read your email.
    2. Send email as you.
    3. View photos you've uploaded.
    4. View your Google+ Profile (OK, no one cares about this).
    5. Delete documents from your Google Drive.

    In fact, Google lists only three things it can't do: Change your password, delete your account, or authorize payments via Google Wallet. And that's it.

    This doesn't apply under Android for some reason, it's limited solely to iOS.

    • by xvan ( 2935999 )
      It's strange, under Android I was never prompted for any 0Auth validation after choosing to sign in with google. This never happened before, is there a new api for that?
      • by _xeno_ ( 155264 )

        Beats me, I haven't tried the app yet, I was basing my post on this Ars Technica article [arstechnica.com].

        The comments are suggesting that this issue exists for some Android users as well, but not all.

        But, yeah, apparently it skips the part where it asks for permissions (sometimes, always for iOS?) and just gives Niantic full control of your Google account.

  • First the movie studios and their region by region availability but now a video game? Is there some actual reason why a video game of all things isn't availble just anywhere?

    • Books and records (now CDs) had probably had regional distribution rights before movies. (given that movies used to only be shown and theaters and not something an average person could purchase)

    • Re: (Score:2, Informative)

      by Anonymous Coward

      Server load.

      Seriously: http://uk.businessinsider.com/pokemon-go-international-rollout-paused-2016-7 Pokemon Go has been vastly more successful than they had prepared for. Server crashes have been pretty frequent, even with the 'limited' release.

  • by Yvan256 ( 722131 ) on Monday July 11, 2016 @01:31PM (#52490623) Homepage Journal

    SandroRAT does sound like a Pokémon name. Seems legit.

  • "Pokemon Bug Removes $7.5B From Nintendo Market Val"

    FTFY :P

  • by iONiUM ( 530420 ) on Monday July 11, 2016 @01:47PM (#52490757) Journal

    I downloaded the APK from apkmirror which I trust: http://www.apkmirror.com/apk/n... [apkmirror.com].

    Furthermore, I'm running Android Marshmallow and it allows you to grant or deny specific privileges to each app. This app asked for 4 permissions: contact list, camera, location and storage. This is how you know it's "authentic".

    If it's asking for more than that (i.e. microphone), you've got a malware ridden copy.

    • by Anonymous Coward

      For 0.29.0,
      md5: 2580d2687af1ffaaec16ff3b48380f76
      sha256: 8bf2b0865bef06906cd854492dece202482c04ce9c5e881e02d2b6235661ab67

  • by Anonymous Coward

    If you installed it from APK Mirror already, Proofpoint said that the SHA-256 for the one they believe to be clean is : 8bf2b0865bef06906cd854492dece202482c04ce9c5e881e02d2b6235661ab67

    The infected one has a hash of: 15db22fd7d961f4d4bd96052024d353b3ff4bd135835d2644d94d74c925af3c4

  • by watermark ( 913726 ) on Monday July 11, 2016 @02:09PM (#52490919)

    I'm not sure it gets any more "news for nerds" than this

  • OK, I know several people with android phones who've had to go to unusual lengths to get it running. I'm fortunate, in that I have an antiquated (?) S3, so it won't run anyway.

    But what methods could they use to determine if they have this?

  • This apk infects your pokemon with pokérus so they power up faster. Download while it lasts folks.
  • Gonna catch something!

  • "Illegal copy of software has a virus".. Oh what a surprise. Is this just a poor attempt to have a dig at Android?
  • dsjafdifasindsainsdin

TRANSACTION CANCELLED - FARECARD RETURNED

Working...