Pulser_G2 · May 26, 2013 at 09:00 am

Sky UK Apps Compromised on Play Store, Uninstall Them!

sky_apps_playstore_hacked

Today is Sunday, 26th May, and across the world, many people have woken up following a leisurely lie-in to the small notification of an updated app being available. Nothing unusual there, or so you’d think.

The only difference is that today, some of these app updates may well have been malicious updates, pushed to some of the Sky UK official Android apps. As reported by PC Pro and Android Police; the  Sky Go, Sky+, SKY WiFi, and Sky News apps all appeared to be targeted in the attacks that involved updates being pushed to the Google Play Store for these applications.

Fortunately, the compromise was more than a little obvious, with the app listing being defaced, including the header banner, description, and screenshots of the Play Store listing, which have since been removed (Thanks to AndroidPolice for the image).

Obviously, the best advice here is to uninstall any Sky apps that you have installed. This ought to alleviate most risk (unless these apps contained an unknown, zero-day exploit that permitted them to break beyond the application container). This is highly unlikely though, and uninstalling the app should be sufficient a precaution to take.

The question here is: Would anyone have noticed this attack had the Play Store listing not been visibly changed? Had the listing not been defaced, would anyone be aware of this surreptitious update which had been installed? I believe nobody would be aware, and everyone would be sitting, none-the-wiser, with a ticking time-bomb on their phones and tablets. These are not small-time apps, with the Sky Go app having between 1 and 5 million users, so the potential for building a silent bot-net of devices is not insignificant.

Later today, we’ll take a dive in and look at the implications of this attack, and what it means for app developers, and users alike. In the meantime, stay safe, and uninstall any Sky apps on your phone. Doing this, you should be reasonably protected against any further risks of this compromise.

Finally, one last piece of advice for Sky or anyone else affected by a similar security incident in the future: When you do announce the breach via Twitter, please do so and link to something verifiable on your own website that details it (in light of recent Twitter accounts being hacked), rather than making a grammatically incorrect and rushed tweet that raises the question of if your Twitter account is compromised:

skysecurityfail

 [Source: AndroidPolice; PC Pro]


_________
Want something on the XDA Portal? Send us a tip!
TAGS:

Pulser_G2

Pulser_G2 is an editor on XDA-Developers, the largest community for Android users. Developer Admin at xda-developers, interested in everything in mobile and security. A developer and engineer, who would re-write everything in C or Assembler if the time was there. View Pulser_G2's posts and articles here.
Mario Tomás Serrafero · Jul 30, 2015 at 02:04 pm · 3 comments

What Do You Think About Fingerprint Scanners?

More and more phones are featuring fingerprint scanners, and with many promising developments and it being natively supported on Android M, we can soon expect to see them on smartphones everywhere. If done right, it is a useful feature that allows for quick unlocking and authorization. There are concerns regarding security, but nonetheless the industry seems to be embracing it with open arms. What do you think?

DISCUSS
Aamir Siddiqui · Jul 30, 2015 at 01:20 pm · no comments

What’s Next for Samsung and Its Flagships?

If we were to say that the Galaxy S6 was a leap of faith made by Samsung, we wouldn't be too wrong. After all, the device marked a definite change in how Samsung perceived the market and its own place in it, as it stood amongst the signs of decline which started with the critical reception of the Galaxy S5. To recap, the Samsung Galaxy S5 was criticized heavily for feeling more like a toy, rather than a premium flagship...

XDA NEWS
Eric Hulse · Jul 30, 2015 at 12:24 pm · 2 comments

The Ultimate Showcase of dBrand Skins

In the search for ways to protect, accessorize, and personalize; a user has many options. One could choose a case, a “skin”, “armor”, or “wraps.” In fact, the global mobile accessory market is poised to reach a high of $62 Billion in 2017. dBrand is one of the more creative and friendly vinyl skin manufacturers around. In hopes of sharing what they can offer, our friends at dBrand sent us over some skins to have a look at. They offer...

XDA NEWS