Hacker News new | ask | show | jobs
by techntoke 2154 days ago
Can you please tell me what app stores you're referring to, and which apps on F-Droid currently contain malware?
2 comments

Here's an article from from April this year 2020

https://www.techradar.com/news/phantomlance-malware-breaches...

Dozens of malicious apps infected with the malware are being distributed via the Play Store and alternate app stores such as APKpure and APKCombo, often targeting users to spy on their habits and steal data.

According to security firm Kaspersky, this malware campaign has been live for over 4 years, and is likely the work of the OceanLotus advanced persistent threat (APT) group, thought to be based out of Vietnam.

So its on playstores and has no relevance to alternatibe playstores or sideloadimg
> and alternate app stores such as APKpure and APKCombo

From GP’s quote directly above.

So? If it already on the pfficial appstore, its not the fault of alternative apstores.
I can tell you about an app that you might have heard of that bypassed the Google Play Store and was a security nightmare.

https://www.cnet.com/news/just-as-critics-feared-fortnite-fo...

> Fortnite became available for Android on Aug. 9, starting with Samsung Galaxy devices, and then became available for all of Android on Aug. 12. Google brought the vulnerability to Epic Games' attention on Aug. 15. Epic Games immediately acknowledged its mistake and fixed the bug with version 2.1.0 of the launcher on Aug. 16.

Iirc the issue was that they first downloaded a file and then ran it. Thus there was a short window of time where someone can tamper with the file before it's running. Far from being a security nightmare it was a subtle flaw, and fixed quickly.