Today is Sunday, 26th May, and across the world, many people have woken up following a leisurely lie-in to the small notification of an updated app being available. Nothing unusual there, or so you’d think.
The only difference is that today, some of these app updates may well have been malicious updates, pushed to some of the Sky UK official Android apps. As reported by PC Pro and Android Police; the Sky Go, Sky+, SKY WiFi, and Sky News apps all appeared to be targeted in the attacks that involved updates being pushed to the Google Play Store for these applications.
Fortunately, the compromise was more than a little obvious, with the app listing being defaced, including the header banner, description, and screenshots of the Play Store listing, which have since been removed (Thanks to AndroidPolice for the image).
Obviously, the best advice here is to uninstall any Sky apps that you have installed. This ought to alleviate most risk (unless these apps contained an unknown, zero-day exploit that permitted them to break beyond the application container). This is highly unlikely though, and uninstalling the app should be sufficient a precaution to take.
The question here is: Would anyone have noticed this attack had the Play Store listing not been visibly changed? Had the listing not been defaced, would anyone be aware of this surreptitious update which had been installed? I believe nobody would be aware, and everyone would be sitting, none-the-wiser, with a ticking time-bomb on their phones and tablets. These are not small-time apps, with the Sky Go app having between 1 and 5 million users, so the potential for building a silent bot-net of devices is not insignificant.
Later today, we’ll take a dive in and look at the implications of this attack, and what it means for app developers, and users alike. In the meantime, stay safe, and uninstall any Sky apps on your phone. Doing this, you should be reasonably protected against any further risks of this compromise.
Finally, one last piece of advice for Sky or anyone else affected by a similar security incident in the future: When you do announce the breach via Twitter, please do so and link to something verifiable on your own website that details it (in light of recent Twitter accounts being hacked), rather than making a grammatically incorrect and rushed tweet that raises the question of if your Twitter account is compromised: