How Can Trojan Apps Steal Mobile Account Data?

1.3K views
•
April 16, 2014
by
RSAC Cybersecurity
YouTube video player
How Can Trojan Apps Steal Mobile Account Data?

TL;DR

A Trojanized mobile app can harvest stored authentication tokens and private application data, upload them to a server, and import them onto another device. The demonstrated attack cloned access to services including Gmail, Calendar, GitHub, and Salesforce without re-entering passwords, showing why rooted devices, outdated software, untrusted app sources, and lost phones create serious privacy risks.

Transcript

Thanks. Uh, good morning, everybody. Thanks for joining me on this beautiful morning. Uh, my name is Kevin Watkins. I... One of the co-founders for Appthority, and we, we do, uh, app reputation and, and intelligence and analyze apps. And I'm gonna talk about mobile app privacy gone in six seconds, and I'll actually do a live demo. A-and it's-- Sinc... Read More

Key Insights

  • Rooted or jailbroken devices are more exposed because applications can gain access across the mobile platform. The demonstration used root elevation to install a modified application without requesting added permissions, allowing it to harvest protected account and application information in the background.
  • A Trojanized application can appear functional while stealing data. The modified Flappy Birds game launched and remained playable as hidden code collected account databases, authentication information, application data, and other private material before transferring the package to a server.
  • Stored authentication tokens can permit account access without another password entry. After the extracted information was imported onto a second device, several applications used the transferred credentials or tokens to access services associated with the original user.
  • Two-factor authentication did not prevent the demonstrated account cloning because an existing private password or authentication token was copied from the compromised device. The second device accessed Google services without repeating the expected password and text-based verification process.
  • Mobile applications are often the weakest link in the presented attack path. Physical possession, a fake charging station, or a lost phone could expose data, but the presenter identified a Trojan application as the primary and most practical delivery method.
  • Corporate and personal data can be compromised through the same token-theft technique. The cloned device exposed calendar information, corporate source code through GitHub, Salesforce data, Google services, medical applications, social accounts, and other authenticated mobile services.
  • Conventional mail gateways were not expected to detect the modified application sent by email. The presenter argued that Trojanized applications could be altered and circulated easily, especially when a popular application was no longer available through its official marketplace.
  • Practical protection depends on reducing device and application exposure. Users should keep platform software current, avoid rooting or jailbreaking, install applications from reputable sources, remotely wipe lost phones, review installed applications, and inspect account access logs whenever those records are available.

Install to Summarize YouTube Videos and Get Transcripts

Explore YouTube Video Summarizer or Get YouTube Transcript Extractor

Questions & Answers

Q: How can a Trojan app steal private data from a phone?

A Trojan app can contain hidden code that runs while the visible application behaves normally. In the demonstration, a modified Flappy Birds app harvested the account database, authentication information, application data, and other private material from a rooted device. It then transferred that information to a local FTP server, allowing the collected data to be imported onto another phone.

Q: Why are rooted or jailbroken phones vulnerable to malicious apps?

Rooting or jailbreaking exposes more of the mobile platform to applications. In the demonstration, root elevation allowed the modified game to install without requesting added permissions and then access information belonging to other applications. The presenter therefore advised users not to root or jailbreak a device unless they understand the consequences, and ultimately recommended avoiding the practice.

Q: How can stolen authentication tokens bypass two-factor authentication?

Two-factor authentication may not trigger when an attacker copies an authentication token or private password that already represents an approved session. The presenter extracted such information from the original phone and imported it onto another device. Google services then became accessible without entering the account password again or repeating the text-based verification step used during the initial sign-in process.

Q: What information was cloned onto the second mobile device?

The imported package produced an apparent mirror of the original device, including its background, applications, private application data, and authentication information. The presenter demonstrated access involving Calendar, GitHub, Salesforce, and Google services. The cloned access exposed both personal information and work resources, including corporate source code available through the authenticated GitHub application.

Q: Can a familiar mobile game hide a data-stealing backdoor?

A familiar game can be modified to include a backdoor while continuing to provide its expected visible function. The demonstrated Flappy Birds package opened as a playable game, but hidden activity underneath harvested and transferred private data. Because users could focus on the functioning game, the malicious collection could occur without an obvious interruption or a separate permission prompt on the rooted device.

Q: Why should mobile apps come from reputable stores?

Applications from third-party sites can be modified and redistributed with malicious code, as illustrated by the Trojanized Flappy Birds package. The presenter acknowledged that Google Play and iTunes had weaknesses and criticized their vetting, but still described reputable stores as a safer choice than third-party sources. An application removed from its official market creates particular opportunities for unsafe copies to circulate.

Q: What should a user do after losing a mobile phone?

A lost phone should be remotely wiped when possible, rather than relying only on its lock. The presenter warned that someone with physical access could still extract stored private information and authentication material. Remote wiping is intended to remove that data before it can be copied, although the recommendation depends on the owner having a remote-wipe capability available for the missing device.

Q: How can users detect copied mobile authentication tokens?

Users should inspect account access logs and review the applications installed on their devices whenever those options are available. The presenter noted that many applications provide little visibility into whether an account token is operating on another phone. Google offered somewhat better information about accessing devices and locations, but those records were described as buried and less accessible than users might expect.

Summary & Key Takeaways

  • A modified Flappy Birds app was installed on a rooted mobile device and silently harvested account databases, authentication information, application data, and the device background. It transferred the collected material to a local FTP server while the game remained playable, illustrating how an apparently familiar application can conceal extensive data theft.

  • The presenter imported the stolen data onto a baseline device and created a functional mirror containing applications, settings, and authenticated access. Services including Calendar, GitHub, Salesforce, and Google services accepted the transferred credentials or tokens. This allowed access to private and corporate information without requiring the original account passwords again.

  • Recommended protections include avoiding rooting or jailbreaking, installing current platform software, using gatekeepers, and obtaining applications from reputable stores rather than third-party sites. A lost phone should be remotely wiped when possible. Users should also inspect account access logs and installed applications, although many services provide limited visibility into unauthorized device access.


Read in Other Languages (beta)

Share This Summary 📚

Explore More Summaries from RSAC Cybersecurity 📚