Tag Archive for: Nexus

Fans of third-party YouTube apps should watch out for Nexus banking malware


It first appeared in June last year and is now being openly advertised by its creators on hacker forums to increase its reach. Nexus’ primary targets are 450 banking and cryptocurrency apps. 

It’s being distributed through phishing websites posing as legitimate websites of YouTube Vanced, a discontinued third-party YouTube app. It uses all the tricks in the books to gain your banking info and take over your financial accounts.

Nexus asks for 50 permissions and abuses at least 14 of them

It is capable of performing overlay attacks, i.e. replicating a legitimate interface to trick you into entering your credentials, and uses keylogging to record your keystrokes. It can even steal SMS messages to get access to two-factor authentication codes and can abuse Accessibility Services to steal information from crypto wallets, 2-Step Verification codes generated by Google Authenticator, and website cookies. The trojan can also delete messages received by you.

After it’s installed on a device, Nexus connects to its command-and-control (C2) server. C2s are used by cybercriminals to control malware, launch attacks, and receive stolen data.

Nexus is said to be in the beta stage but it’s already being used by many threat actors to carry out nefarious activities. Cybercriminals who do not know how to make their own malware can rent it for $3,000 a month.

It looks like the developer is from a CIS (Commonwealth of Independent States) country and has prohibited the trojan’s use in Azerbaijan, Armenia, Belarus, Kazakhstan, Kyrgyzstan, Moldova, Russian Federation, Tajikistan, Uzbekistan, Ukraine, and Indonesia.

Nexus is capable of updating itself and Cleafy thinks it is a real threat and can infect hundreds of Android devices in the world.

To protect yourself from infections, try to only download apps from Google Play and enable Google Play Protect. Use strong passwords and enable biometric security features where possible and be very careful when granting permissions.

Source…

December 2018 security patch arrives for Pixel, Nexus, Essential Phone, and 2016 Pixels – Android Authority

  1. December 2018 security patch arrives for Pixel, Nexus, Essential Phone, and 2016 Pixels  Android Authority
  2. [Update: 2016 Pixel] December security patch rolling out to Pixel & Nexus, factory images and OTAs live  9to5Google
  3. Google begins rolling out December Android security patch, squashing annoying Pixel 3 bugs  Neowin
  4. December security update brings fixes for memory, camera, and more to the Google Pixel smartphones  XDA-Developers
  5. Google Starts Rolling Out December Android Security Update for Pixel & Nexus Smartphones  PhoneRadar
  6. View full coverage on read more

“android security news” – read more

[Update: 2016 Pixel] December security patch rolling out to Pixel & Nexus, factory images and OTAs live – 9to5Google

  1. [Update: 2016 Pixel] December security patch rolling out to Pixel & Nexus, factory images and OTAs live  9to5Google
  2. Google begins rolling out December Android security patch, squashing annoying Pixel 3 bugs  Neowin
  3. December security update brings fixes for memory, camera, and more to the Google Pixel smartphones  XDA-Developers
  4. December 2018 security patch arrives for Pixel, Nexus, and Essential Phone  Android Authority
  5. Google Starts Rolling Out December Android Security Update for Pixel & Nexus Smartphones  PhoneRadar
  6. View full coverage on read more

“android security news” – read more

Google starts rolling out November Android security patches, the last for the Nexus devices

  1. Google starts rolling out November Android security patches, the last for the Nexus devices  Neowin
  2. Full coverage

android security news – read more