Friday, February 21, 2025
HomeMobile AttacksMillions of Android Phones including latest Versions Vulnerable to Cloak & Dagger...

Millions of Android Phones including latest Versions Vulnerable to Cloak & Dagger attack

Published on

SIEM as a Service

Follow Us on Google News

Cloak & Dagger attack discovered by security experts from Georgia Institute of Technology, which allows attackers to get complete control over your device.

These attack just require two permission that, in the event that the application is installed from the Play Store, the client does not require to grant permission and even the users are not notified.

Users don’t get notified about this malicious activity, and it will affect all the versions of Android including (including the latest version, Android 7.1.2).

Permissions for Takeaway

Permission abused by Cloak and Dagger attacks

  • SYSTEM_ALERT_WINDOW (“draw on top”).
  • BIND_ACCESSIBILITY_SERVICE (“a11y”).

If the user installed the malicious app from Google play store, the user’s not required to give any permission to get succeed with this attack, and it doesn’t show any indication to the user.

In this situation “draw on top” is simply possible, and this authorization is sufficient to bait the client into unconsciously enabling a11y (through clickjacking).

The conceivable attacks incorporate progressed clickjacking, unconstrained keystroke recording, stealthy phishing, the quiet establishment of a God-mode application (with all authorizations permissions), and silent phone crack + arbitrary activities (while keeping the screen off).

Possible attacks due to Permission Issue

Security experts from Cloak & Dagger highlighted various possible attacks due to this permission issues:

“draw on top” permission

  • Context-aware clickjacking & Context hiding (Enabling accessibility).
  • Invisible Grid Attack (keyboard Sniffer).

“accessibility service” permission

  • Keystroke recording.
  • Web exploration.
  • Ad hijacking.
  • Device unlocks through PIN Injection.
  • Hijacking two-factor Auth Tokens.

With Both permissions

  • Silent installation.
  • Stealthy phishing.

Video PoC of the attacks by security experts at Cloak and Dagger.

Infected version

  • Android 5.1.1 (32.0%*)
  • Android 6.0.1 (31.2%)
  • Android 7.1.2 (7.1%)

Recommended for users

Security specialists from Cloak and Dagger recommend users to check which applications approach the “draw on top” and the a11y authorizations.

To moderate the issue and cripple the Cloak and Dagger assaults in Android 7.1.2 it is conceivable to disable the “draw on top” permission:

Android 7.1.2   Settings → Apps → "Gear symbol" → Draw over Other Apps.

Also Read

Gurubaran
Gurubaran
Gurubaran is a co-founder of Cyber Security News and GBHackers On Security. He has 10+ years of experience as a Security Consultant, Editor, and Analyst in cybersecurity, technology, and communications.

Latest articles

SPAWNCHIMERA Malware Exploits Ivanti Buffer Overflow Vulnerability by Applying a Critical Fix

In a recent development, the SPAWNCHIMERA malware family has been identified exploiting the buffer...

Sitevision Auto-Generated Password Vulnerability Lets Hackers Steal Signing Key

A significant vulnerability in Sitevision CMS, versions 10.3.1 and earlier, has been identified, allowing...

NSA Allegedly Hacked Northwestern Polytechnical University, China Claims

Chinese cybersecurity entities have accused the U.S. National Security Agency (NSA) of orchestrating a...

ACRStealer Malware Abuses Google Docs as C2 to Steal Login Credentials

The ACRStealer malware, an infostealer disguised as illegal software such as cracks and keygens,...

Supply Chain Attack Prevention

Free Webinar - Supply Chain Attack Prevention

Recent attacks like Polyfill[.]io show how compromised third-party components become backdoors for hackers. PCI DSS 4.0’s Requirement 6.4.3 mandates stricter browser script controls, while Requirement 12.8 focuses on securing third-party providers.

Join Vivekanand Gopalan (VP of Products – Indusface) and Phani Deepak Akella (VP of Marketing – Indusface) as they break down these compliance requirements and share strategies to protect your applications from supply chain attacks.

Discussion points

Meeting PCI DSS 4.0 mandates.
Blocking malicious components and unauthorized JavaScript execution.
PIdentifying attack surfaces from third-party dependencies.
Preventing man-in-the-browser attacks with proactive monitoring.

More like this

CISA Released Secure Mobile Communication Best Practices – 2025

The Cybersecurity and Infrastructure Security Agency (CISA) has released new best practice guidance to...

Ghost Tap Attack, Hackers Stolen Credit Card Linked To Google Pay Or Apple Pay

Threat actors are exploiting a new cash-out tactic called "Ghost Tap" to siphon funds...

HookBot Malware Use Overlay Attacks Impersonate As Popular Brands To Steal Data

The HookBot malware family employs overlay attacks to trick users into revealing sensitive information...