Categories: NewsSecurity

Cloak and Dagger Attack Targets Android Users Worldwide

Android users all over the world remain a very popular target for criminals looking to obtain specific information. A new type of Android-only attack has been identified, which goes by the name of “Cloak and Dagger”. What makes this attack so powerful – and troublesome – is how it can run secretly on a phone without the user noticing anything. Moreover, the hackers responsible for these attacks can log information and remotely install software on the device.

Cloak and Dagger Is A Problem For Android Users

It is not the first time Android users have to deal with a major attack. Nor is it the first time such an attack is virtually undetectable by the device user. Cloak and Dagger is nothing new based on these parameters, but that doesn’t mean people should dismiss the threat so easily either. In fact, having a malicious tool capable of logging keystrokes and installing apps remotely is a major problem.

To be more specific, this new exploit makes use of a bug found in the Android UI. Moreover, it only requires two specific permissions to start causing havoc, which is quite troublesome. More importantly, neither of these permissions requires root access, indicating the exploit can be used against virtually any Android device in the world right now. It is only a matter of time until a security update is released, though.

Researchers are quite concerned about this exploit, considering the Android operating system automatically grants one of the two required permissions automatically. That is, assuming the software is downloaded from the Google Play Store in the first place. Furthermore, the assailants can easily trick users into granting the second permission. All it takes is hiding a layer of malicious activity below what the user sees on the screen, and the chances of success increase exponentially in the process.

Related Post

This is partially what makes the Cloak and Dagger attack so dangerous. Users who are affected by this exploit won’t even notice anything is wrong, as their interactions with the Android device will look like normal. However, it is the software running below the visual layer that is of major concern. Keylogging information and remotely installing apps on the phone are just a few of the potential consequences.

Security researchers are even more concerned about how the accessibility app can be used to unlock the phone and interact with other applications even when the device’s screen is completely turned off. It is unclear what an attacker could do with this, although we do know the malicious activity will remain hidden from the user. It is also an excellent way for assailants to completely erase tracks of any wrongdoings, as the user would never know something has occurred.

Thankfully, Google has been made aware of this problem, and their engineers are already working on a solution. It is evident the researchers discovering this exploit want to ensure the Android ecosystem is safe at all times. Google Play Protect has been updated to detect and prevent installation of applications looking to execute code beneath the visual layer of the Android device in question.

If you liked this article, follow us on Twitter @themerklenews and make sure to subscribe to our newsletter to receive the latest bitcoin, cryptocurrency, and technology news.

JP Buntinx

JP Buntinx is a FinTech and Bitcoin enthusiast living in Belgium. His passion for finance and technology made him one of the world's leading freelance Bitcoin writers, and he aims to achieve the same level of respect in the FinTech sector.

Share
Published by
JP Buntinx

Recent Posts

Bitwise Launches Its First Tokenized Fund With $259M in Assets and 4% Annual Yield

Bitwise Asset Management has just made its first move into tokenized funds, and it comes…

21 hours ago

Binance Launches US Stocks and ETFs Trading for Non-US Users With Zero Commission

Binance just made a move that blurs the line between crypto exchange and traditional brokerage…

22 hours ago

NEAR Protocol Ships Confidential Payments, Crosses $19B in Intents Volume, and Partners With Bermuda Government

NEAR Protocol has had a month that most blockchain projects would stretch across an entire…

2 days ago

Chainlink Records 7 New Integrations Across 6 Services and 4 Chains

Something is becoming increasingly clear about Chainlink, the integrations are not slowing down. The protocol…

2 days ago

Circle Freezes $12.6 Million in Zama’s Confidential USDC Contract on Ethereum

Blockchain investigator ZachXBT has flagged a major stablecoin freeze that is sending shockwaves through the…

3 days ago

Exponent Finance Launches V2 To Expand Institutional Yield Markets On Solana

From a primarily interest rate swap niche product, Exponent has developed into an onchain capital…

4 days ago