December 4, 2019 By Shane Schick 2 min read

An in-app security vulnerability dubbed StrandHogg is being exploited in at least 36 Android apps and triggering malicious code, researchers warned.

Initially discovered by Promon and Lookout, the flaw allows cybercriminals to take advantage of the way Android handles more than one process at a time, depending on which app is being displayed to a user. This means that, even while using a legitimate app, victims could be activating malware that shows phishing pages or asks for permissions that give cybercriminals unauthorized access to their device.

StrandHogg was discovered after financial institutions in the Czech Republic said they were seeing money disappear from customers’ accounts, the researchers said.

Second-Stage Payloads

The attacks most likely began after Android users downloaded malicious apps through the Google Play store, according to the report. Apps infected with StrandHogg were then downloaded separately, rather than through Google Play. This makes them second-stage payloads, according to the research.

All it takes is a tap of an app icon for the malicious code to execute through a feature in Android called task reparenting. Smartphone users probably wouldn’t notice this, however, and might easily assume any login screens or permission requests that pop up are legitimate.

Developers with the Android project were informed of the flaw more than three months ago but have yet to issue a fix, researchers added.

Unfortunately, StrandHogg could be used to wage malware attacks through the 500 most popular apps in the Google Play store, according to the report. This is true across all versions of Android up to the most recent, Android 10. Root access is unnecessary for the bug to be exploited, based on the researchers’ findings.

Stop StrandHogg Before It Starts

IBM experts recently noted a rise in evil downloaders in the Android mobile malware kill chain and suggested taking a close second look at apps that might be fake. These often betray themselves with a small file size and badly written descriptions, as well as design that looks a lot poorer in quality than legitimate apps.

If you’re not sure whether a device has been infected, though, there are tools available to detect malicious apps and identify those that would have been blacklisted by an IT department.

More from

FYSA – Adobe Cold Fusion Path Traversal Vulnerability

2 min read - Summary Adobe has released a security bulletin (APSB24-107) addressing an arbitrary file system read vulnerability in ColdFusion, a web application server. The vulnerability, identified as CVE-2024-53961, can be exploited to read arbitrary files on the system, potentially leading to unauthorized access and data exposure. Threat Topography Threat Type: Arbitrary File System Read Industries Impacted: Technology, Software, and Web Development Geolocation: Global Environment Impact: Web servers running ColdFusion 2021 and 2023 are vulnerable Overview X-Force Incident Command is monitoring the disclosure…

What does resilience in the cyber world look like in 2025 and beyond?

6 min read -  Back in 2021, we ran a series called “A Journey in Organizational Resilience.” These issues of this series remain applicable today and, in many cases, are more important than ever, given the rapid changes of the last few years. But the term "resilience" can be difficult to define, and when we define it, we may limit its scope, missing the big picture.In the age of generative artificial intelligence (gen AI), the prevalence of breach data from infostealers and the near-constant…

Airplane cybersecurity: Past, present, future

4 min read - With most aviation processes now digitized, airlines and the aviation industry as a whole must prioritize cybersecurity. If a cyber criminal launches an attack that affects a system involved in aviation — either an airline’s system or a third-party vendor — the entire process, from safety to passenger comfort, may be impacted.To improve security in the aviation industry, the FAA recently proposed new rules to tighten cybersecurity on airplanes. These rules would “protect the equipment, systems and networks of transport…

Topic updates

Get email updates and stay ahead of the latest threats to the security landscape, thought leadership and research.
Subscribe today