Connect with us

Apps

ESET Research Uncovers APT-C-23 Group’s New Android Spyware

Published

on

ESET researchers have analyzed a new version of Android spyware used by APT-C-23, a threat group active since at least 2017 that is known for mainly targeting the Middle East The new spyware, detected by ESET security products as Android/SpyC23.A, builds upon previously reported versions with extended espionage functionality, new stealth features and updated C&C communication. One of the ways the spyware is distributed is via a fake Android app store, impersonating well-known messaging apps, such as Threema and Telegram, as a lure.

ESET researchers started investigating the malware when a fellow researcher tweeted about an unknown, little-detected Android malware sample in April 2020. “A collaborative analysis showed that this malware was part of the APT-C-23 arsenal – a new, enhanced version of their mobile spyware,” explains Lukáš Štefanko, the ESET researcher who analyzed Android/SpyC23.A.

The spyware was found lurking behind seemingly legitimate apps in a fake Android app store. “When we analyzed the fake store, it contained both malicious and clean items. The malware was hiding in apps posing as AndroidUpdate, Threema and Telegram. In some cases, victims would end up with both the malware and the impersonated app installed,” comments Štefanko.

After installation, the malware requests a series of sensitive permissions, disguised as security and privacy features. “The attackers used social engineering-like techniques to trick victims into granting the malware various sensitive rights. For example, permission to read notifications is masked as a message encrypting feature,” details Štefanko.

Once initialized, the malware can carry out a range of espionage activities based on commands from its C&C server. Besides recording audio; exfiltrating call logs, SMS and contacts; and stealing files, the updated Android/SpyC23.A can also read notifications from messaging apps, make screen and call recordings, and dismiss notifications from some built-in Android security apps. The malware’s C&C communication has also undergone an update, making the C&C server more difficult to identify for security researchers.

The APT-C-23 group is known to have used both Windows and Android components in its operations, with the Android components first described in 2017 by Qihoo 360 Technology under the name Two-tailed Scorpion.Since then, multiple analyses of APT-C-23’s mobile malware have been published. Android/SpyC23.A – the group’s latest spyware version – features several improvements making it even more dangerous to victims.

“To stay safe from spyware, we advise Android users to only install apps from the official Google Play Store, double-check the permissions requested, and use a trustworthy and up-to-date mobile security solution,” concludes Štefanko.

Click to comment

You must be logged in to post a comment Login

Leave a Reply

Apps

Google’s Latest AI Model Enables Watermark Removal from Images

Published

on

A potentially controversial application of Google’s new Gemini 2.0 Flash AI model has emerged: users are leveraging it to remove watermarks from images, including those from stock photo sites such as Getty Images.

The recently expanded image generation feature of Gemini 2.0 Flash allows for native image generation and editing, a powerful tool that seemingly lacks robust usage restrictions. Social media users have highlighted how the AI can not only remove watermarks but also intelligently fill in the resulting gaps, often with impressive accuracy, and it’s currently free within Google’s AI Studio developer tools.

While labeled “experimental” and “not for production use,” Gemini 2.0 Flash’s ability to bypass watermarks stands in contrast to models like Anthropic’s Claude 3.7 Sonnet and OpenAI’s GPT-4o, which explicitly prohibit such actions, citing ethical and legal concerns.

It’s important to note that Gemini 2.0 Flash isn’t foolproof; it can struggle with semi-transparent or heavily overlaid watermarks. Nevertheless, the ease with which it can remove watermarks raises potential copyright issues, as removing a watermark without the copyright holder’s permission is generally illegal in many countries. This situation underscores the ongoing challenges of balancing powerful AI capabilities with copyright protection.

Continue Reading

Apps

Smiles Partners with Amazon.ae to Offer Amazon Prime Offers to UAE Customers

Published

on

Shopping, streaming, and savings are set to get much better and more rewarding as Smiles, the UAE’s premier everyday rewards SuperApp, teams up with Amazon.ae to offer customers in the UAE up to 6 months of Amazon Prime, using Smiles points. With this collaboration, customers can now subscribe to an Amazon Prime membership directly on the Smiles app at discounted prices of up to 58 per cent, courtesy of Smiles. Customers have the flexibility to redeem their Smiles Points against the subscription or pay using their credit card, earning additional points with every purchase.

Khaled ElKhouly, Chief Consumer Officer, e& UAE, said, “Our collaboration with Amazon is all about bringing real value and convenience to our customers. By offering discounts on Amazon Prime subscriptions through the Smiles app, we’re making it easier to Reward Your Everyday while enjoying the best in shopping, entertainment, and savings.” Smiles customers can now subscribe to a 3 or 6-month Amazon Prime membership at a promotional rate through the Smiles app.

3-Month Promotion:

  1. Available for just AED24 on the Smiles app (retail price at AED48)—a 50 per cent discount. Customers can redeem this offer using
  2. 3,000 Smiles Points or pay via credit/debit card.

6-Month Promotion:

  1. Available for only AED40 on the Smiles app (retail price at AED96)—a 58 per cent discount. Customers can redeem this offer using
  2. 5,000 Smiles Points or pay via credit/debit card.

After the promotional period, customers will automatically be billed AED16/month by Amazon.ae to continue enjoying their Amazon Prime membership benefits. This collaboration brings together the best of both worlds for customers in the UAE, combining Smiles’ innovative rewards ecosystem with the incremental value of Amazon Prime shopping, convenience and entertainment benefits.

Smiles, the UAE’s leading everyday rewards SuperApp, boasts a community of over five million loyal members. It empowers customers to earn and redeem points for a wide range of daily activities, including ordering food and groceries, booking home services, dining out, shopping, entertainment, travelling, and much more. “Reward Your Everyday” underscores Smiles’ commitment to enhancing every aspect of daily life and integrating the SuperApp more deeply into the lifestyles of UAE residents by making each interaction convenient and rewarding and delivering unmatched value and convenience to its customers.

Prime continues to be the best way to enjoy Amazon, offering members a wide range of benefits such as Free Same-Day and One-Day Delivery, Free International Delivery from Amazon US, UK and Germany and access to Prime Video and Prime Gaming.

Continue Reading

Apps

Apple Invites App Simplifies Gathering for Special Occasions

Published

on

Apple today introduced Apple Invites, a new app for iPhone that helps users create custom invitations to gather friends and family for any occasion. With Apple Invites, users can create and easily share invitations, RSVP, contribute to Shared Albums, and engage with Apple Music playlists. Starting today, users can download Apple Invites from the App Store, or access it on the web through icloud.com/ae/invites. iCloud+ subscribers can create invitations, and anyone can RSVP, regardless of whether they have an Apple Account or Apple device.

“With Apple Invites, an event comes to life from the moment the invitation is created, and users can share lasting memories even after they get together,” said Brent Chiu-Watson, Apple’s senior director of Worldwide Product Marketing for Apps and iCloud. “Apple Invites brings together capabilities our users already know and love across iPhone, iCloud, and Apple Music, making it easy to plan special events.”

To get started with Apple Invites, users can choose an image from their photo library or the app’s gallery of backgrounds — a curated collection of images representing different occasions and event themes. Integrations with Maps and Weather give guests directions to the event and the forecast for that day.

Additionally, participants can easily contribute photos and videos to a dedicated Shared Album within each invite to help preserve memories and relive the event. Collaborative playlists allow Apple Music subscribers to create a curated event soundtrack that guests can access right from Apple Invites.

With Apple Intelligence, creating unique event invitations is easy. Users can tap into the built-in Image Playground experience to produce original images using concepts, descriptions, and people from their photo library. When composing invitations, users can use Writing Tools to help find just the right turn of phrase to meet the moment.

Hosts get full control of their invite experience: They can easily view and manage their events, share invitations with a link, review RSVPs, and choose the details they want included in the preview, like the event background or a home address. Guests can view and respond to an invitation using the new iPhone app or on the web without needing an iCloud+ subscription or an Apple Account. Attendees control how their details show up to others, and have the ability to leave or report an event at any time.

In addition to event creation in Apple Invites, iCloud+ subscribers have access to many more premium features:

  • Expanded storage allows users to keep large libraries of original, high-resolution photos, videos, and files safe in iCloud, and easily accessible across all of their devices and the web.
  • Private Relay keeps browsing in Safari entirely private from network providers, websites, and even Apple.
  • Hide My Email generates unique, random email addresses whenever needed.
  • HomeKit Secure Video allows users to capture and review home security footage in an end-to-end encrypted format.
  • Custom email domains enable users to personalize their iCloud email addresses.
  • Family Sharing allows users to share their iCloud+ subscription with up to five people at no extra cost.

Apple Invites is available today as a free download from the App Store for all iPhone models running iOS 18 or later.

Continue Reading
Advertisement
Advertisement

Latest Reviews

Follow us on Facebook