Mar 07, 2023Ravie Lakshmanan
An older version of Shein’s Android application[1]
suffered from a bug that periodically captured and transmitted
clipboard contents to a remote server.
The Microsoft 365 Defender Research Team said it discovered[2]
the problem in version 7.9.2[3]
of the app that was released on December 16, 2021. The issue has
since been addressed as of May 2022.
Shein, originally named ZZKKO, is a Chinese online fast fashion
retailer based in Singapore. The app, which is currently at version
9.0.0, has over 100 million downloads.
The tech giant said[4]
it’s not “specifically aware of any malicious intent behind the
behavior,” but noted that the function isn’t necessary to perform
tasks on the app.
It further pointed out that launching the application after
copying any content to the device clipboard automatically triggered
an HTTP POST request containing the data to the server
“api-service[.]shein[.]com.”
To mitigate such privacy risks, Google has further made
improvements to Android in recent years, including displaying toast messages[5] when an app accesses the
clipboard and barring apps[6]
from getting the data unless it is actively running in the
foreground.
Discover the Latest Malware Evasion Tactics and Prevention
Strategies
Ready to bust the 9 most dangerous myths about file-based
attacks? Join our upcoming webinar and become a hero in the fight
against patient zero infections and zero-day security events!
“Considering mobile users often use the clipboard to copy and
paste sensitive information, like passwords or payment information,
clipboard contents can be an attractive target for cyberattacks,”
researchers Dimitrios Valsamaras and Michael Peck said.
“Leveraging clipboards can enable attackers to collect target
information and exfiltrate useful data.”
Found this article interesting? Follow us on Twitter [8]
and LinkedIn[9]
to read more exclusive content we post.
References
- ^
Android
application (play.google.com) - ^
discovered
(www.virustotal.com) - ^
version
7.9.2 (www.appbrain.com) - ^
said
(www.microsoft.com) - ^
displaying toast messages
(developer.android.com) - ^
barring
apps (developer.android.com) - ^
RESERVE YOUR SEAT
(thn.news) - ^
Twitter
(twitter.com) - ^
LinkedIn
(www.linkedin.com)
Read more https://thehackernews.com/2023/03/sheins-android-app-caught-transmitting.html