If you think you're immune to hackers if you only download legitimate Android apps from Google Play, think again.
Researchers at McAfee Mobile Research have uncovered a new "money-grabbing" campaign, involving at least 15 re-packaged applications that secretly subscribe to paid premium services while users do not pay attention This list includes many applications called "phishing scams" such as Qrcode Scanner, Cut Ringtones 2018 and Despacito Ringtone.
The campaign was launched by AsiaHitGroup Gang, which first appeared in late 2016, targeting the main victims in Thailand and Malaysia. This group uses a fake software installer called Sonvpay.A that downloads and installs popular applications that are not released on Google Play, of course with a certain amount of underlay. . But what is worth mentioning here is that it secretly subscribes to paid services in the background for at least 20,000 victims by sending SMS messages to paid phone numbers.
But that is just the beginning.
The group then "captured" Google Play in November 2017, with the second campaign targeting Thailand, Malaysia, and Russia. They modified the fake installer, naming it Sonvpay.B, to download a fake version of the familiar Google Play app. In this campaign, Sonvpay relies on the geographical location of the IP address to identify the country of origin of the victim. It also uses the same SMS method as the first one, plus the WAP Billing feature - billing directly to the network - to secretly register victims into premium services.
Their third campaign began in January of this year, targeting Android devices that visit Google Play in Malaysia and Kazakhstan. Instead of creating fake applications, the team has incorporated legacy Android applications into Sonvpay.C, allowing it to use silent push notifications in the background to secretly register victims into services. premium paid. Applications themselves do not appear to be dangerous, except for requesting access to SMS. In fact, they work just fine.
{
"lightbox_close": "Close",
"lightbox_next": "Next",
"lightbox_previous": "Previous",
"lightbox_error": "The requested content cannot be loaded. Please try again later.",
"lightbox_start_slideshow": "Start slideshow",
"lightbox_stop_slideshow": "Stop slideshow",
"lightbox_full_screen": "Full screen",
"lightbox_thumbnails": "Thumbnails",
"lightbox_download": "Download",
"lightbox_share": "Share",
"lightbox_zoom": "Zoom",
"lightbox_new_window": "New window",
"lightbox_toggle_sidebar": "Toggle sidebar"
}
"The subscription is primarily made through WAP Billing, which does not require sending SMS messages to premium numbers," said Carlos Castillo of McAfee. "Instead, it only requires users to use the network. Mobile to access a specific website and automatically click a button to launch the registration process. "
Once you install one of the other applications, Sonvpay will receive paid premium subscription services through push notifications that phone users will never see. These services are paid directly to the network. In addition, there is a fake "update" component, which requires the user to agree to allow the application to update, and Sonvpay.C will take advantage of that to register for premium services. Even if the user does not agree, these services will still appear in the network invoice depending on the statement sent through the push message.
The problem with the pay-as-you-go model and this type of scam is that usually, users will not notice until they receive monthly receipts. And because this is a subscription model, the victim will have to find out how to stop subscribing to premium services mentioned above.
When the McAfee team discovered Qrcode Scanner, Cut Ringtone 2018 and Despacito Ringtone were attached to Sonvpay.C, they warned Google and the apps were removed from Google Play. Despacito Ringtone reappears after a few days, once again infected with Sonvpay.C, and again be killed by Google.
Certainly AsiaHitGroup Gang will be back with the 4th campaign. Be wary!
Reference: DigitalTrends
This is basically a copy and paste from the following link...
https://www.digitaltrends.com/compu...und-secretly-subscribing-to-premium-services/
~~~~~~~~~~~~~~~
I DO NOT provide support via PM unless asked/requested by myself. PLEASE keep it in the threads where everyone can share.
Related
{
"lightbox_close": "Close",
"lightbox_next": "Next",
"lightbox_previous": "Previous",
"lightbox_error": "The requested content cannot be loaded. Please try again later.",
"lightbox_start_slideshow": "Start slideshow",
"lightbox_stop_slideshow": "Stop slideshow",
"lightbox_full_screen": "Full screen",
"lightbox_thumbnails": "Thumbnails",
"lightbox_download": "Download",
"lightbox_share": "Share",
"lightbox_zoom": "Zoom",
"lightbox_new_window": "New window",
"lightbox_toggle_sidebar": "Toggle sidebar"
}
VPN Gate List
Hi all, thanks for each and every one of you that come into this thread. This is an application I just recently released, it is a unofficial VPN Gate client app.
Market Link: https://play.google.com/store/apps/details?id=net.rejinderi.vpngatelist
VPN Gate is a university project in Japan that promotes open access to all websites/apps without restriction, for more information you can visit their website at http://www.vpngate.net/en/
Quoted from VPN Gate's website
Welcome to VPN Gate. (Launched on March 8, 2013.)
- You can get through your government's firewall to browse restricted websites. (e.g. YouTube.)
- You can disguise your IP address to hide your identity while surfing the Internet.
- You can protect yourself by utilizing the strong encryption while using public Wi-Fi. More Details...
Click to expand...
Click to collapse
What the app does is allows you to source a list of publicly available VPN servers and connect directly via OpenVPN Connect application. It is very simple to use that can be done in a matter of seconds once you got everything set up, what you get is a very secured connection, fast connection (depending on the server of choice) and its free!!!
How to Use
Open the app, the app will start to fetch the list, after you get the list it looks like this, you can search for country or sort the results returned, to refresh use the pull to refresh feature.
Click on your favourite VPN server on the list and enter the result page, click on Import to OpenVPN, it will prompt you to download the app if it doesn't exist, after import is done press connect and Voilà! you're done! :laugh:
Thanks
This is what i was looking for, thank you so much
VPN Unlimited app - best online safeguard for your Android device
VPN Unlimited has 10 days of free trial, download it from Google Play Store and try how it will be working for your Android device
As safety is considered a number one priority especially when it comes to an online security, our Company continues to enhance its line of products and services. We are happy to announce the release of secure VPN Unlimited for Android platform. Looking at the statistics of the Android and its ever-growing popularity, Simplex Solutions Inc. set a goal to deliver the profound VPN service to the renowned OS too. And now when we release the Android VPN version, we can proudly say that that you are assured to stay protected while performing all of your Internet activities.
You can contact our support team directly from the app anytime you need assistance!
Updated app.
This is totally free, no trial or whatsoever FYI. But a lot of countries are blocking them.
Push up for awareness, updated APK, much lower footprint now.
Download APK from 1st post. Thank you.
Actually I don't prefer using free services, I am already using a reliable cheap one, here you can get a big discount https://www.bvpn.me/en/trysmoketunnelfree/
k From where VPN Gate is operating their services ? I personally thing that VPN gate is operating from Korea Republic. Is this right?
However i also read a detail article VPNGate and i knew that vpngate have more then 9k server list :highfive:
Well for further detail here is the best source: vpnranks_com/vpn-gate-review/
Hi all, i released a much better app, https://forum.xda-developers.com/android/apps-games/app-totally-free-vpn-t3124097
please use the new app from now on.
Thank you!
Hi, everyone! I would like to introduce SoundLogin - an app and technology that simplifies two-factor authentication process.
{
"lightbox_close": "Close",
"lightbox_next": "Next",
"lightbox_previous": "Previous",
"lightbox_error": "The requested content cannot be loaded. Please try again later.",
"lightbox_start_slideshow": "Start slideshow",
"lightbox_stop_slideshow": "Stop slideshow",
"lightbox_full_screen": "Full screen",
"lightbox_thumbnails": "Thumbnails",
"lightbox_download": "Download",
"lightbox_share": "Share",
"lightbox_zoom": "Zoom",
"lightbox_new_window": "New window",
"lightbox_toggle_sidebar": "Toggle sidebar"
}
What is SoundLogin?
Two-factor authentication (2FA) adds a layer of protection to the standard password method of online authentication. 2FA is offered by many web-services, such as Twitter, GitHub, Amazon Web Services, Google and many others. However, sometimes using two-factor authentication can be very painful. So, at one point, we decided to apply our technology (audio watermarking) to make life easier for people who rely heavily on two-factor authentication. SoundLogin is not a new proprietary 2FA-solution, it is helper technology that simplifies interaction with conventional 2FA systems that rely on one-time codes sent by SMS or generated by mobile apps such as Google Authenticator or FreeOTP. The SoundLogin is a solution that includes a mobile app and extension for web-browsers (although extension is only needed for compatibility with existing web-services). The SoundLogin mobile app by itself acts as a well-known Google Authenticator or FreeOTP app, and is fully compatible with these apps. However, if you install the SoundLogin browser extension, then you can skip the annoying process of manual entering of one-time passwords.
How it works?
When the user clicks on the one-time code button in the mobile app, the app plays a short notification sound (customizable), which contains an encoded one-time password (OTP). The browser captures that sound, decodes a one-time password and automatically fills in the form on the website. OTP delivery is carried out locally by the sound wave, no data is transferred over Internet, so (a) the mobile application can work off-line, (b) a remote attacker cannot intercept your one-time password. The SoundLogin Android app also provides an option (Opt-in) to extract one-time passwords from SMS messages, and send them to the browser via sound notification automatically or after user confirmation.
Here is the short Demonstration Video
Mobile applications and browser extensions are free of charge and ad-free.
The browser extensions already recognize web-pages of many well-known 2FA-enabled services, but a power user can always add his/her own form filling rules, or you can write to us and we will be happy to add a new 2FA-enabled service to our list.
Project web-site: www.soundlogin.com
Mobile app:
GooglePlay link
Browser extensions:
Chrome Web Store link
Firefox Add-ons link
Opera Add-ons link
Mobile app can be tested without browser extensions here: demo installation of WordPress with SoundLogin-enabled 2FA
App screenshots:
We are looking for your feedback! We don't have any Google Analytics or other tracking software in our app or extensions, so the only way to know how people use SoundLogin is it to get your feedback here.
Any ideas and suggestions are greatly appreciated! Thank you!
NIKI
An AI powered chat bot for online purchases
Niki, an AI-powered bot, is looking for beta users for its voice feature
{
"lightbox_close": "Close",
"lightbox_next": "Next",
"lightbox_previous": "Previous",
"lightbox_error": "The requested content cannot be loaded. Please try again later.",
"lightbox_start_slideshow": "Start slideshow",
"lightbox_stop_slideshow": "Stop slideshow",
"lightbox_full_screen": "Full screen",
"lightbox_thumbnails": "Thumbnails",
"lightbox_download": "Download",
"lightbox_share": "Share",
"lightbox_zoom": "Zoom",
"lightbox_new_window": "New window",
"lightbox_toggle_sidebar": "Toggle sidebar"
}
After around two successful years of launching its Android app, Niki is jumping to the next level by introducing voice feature. Users will now be able to shop for products and a number of services using voice commands. To help shape it better, we are looking for beta testers who can talk to Niki and point out bugs, or suggest improvements!
About Niki
Niki is an AI-powered bot, which happens to be the pioneer in conversational commerce in India. One can pay bills, book movie tickets, buses, hotels, cabs and more by simply chatting with Niki. Our aim is to make Artificial Intelligence accessible to everyone i.e. Businesses and consumers. To consumers, it’s a simple and easy to use chat interface to shop for products and services. To the businesses, it provides a plug and play technology that can be easily integrated everywhere including operating systems, on messaging platforms like Facebook Messenger, and on the brand’s applications (app and web).
One chatbot to rule them all
With around 40+ merchants on board for multiple services, Niki is a one stop shop for everything commerce. Keeping Niki installed, one can replace over 10-15 apps on his/her phone and get tasks done via a single chat window interface. Apart from being an all-in-one shop, Niki aims to be present everywhere. After a Messenger Bot and an Android app, we’re ready to explore other messaging platforms like Slack, and also have plans for an iOS app in the future.
Voice feature
2017 is being called the year of Artificial Intelligence. Although the technology is being explored since years, the new developments have been exciting. Big players such as Google, Apple and Amazon already have their voice-controlled assistants for you. And even when there is immense scope for improvements, they are definitely helping make life easier. The virtual assistants are at your service as soon as you blurt out a command.
Similarly, ordering and making transactions on chat has been a much easier option. We wish to make it even more fun, time-saving and convenient for the end-users, by letting them talk to Niki and get things done.
For this to be successful, we definitely need your help with testing and feedback to improve accuracy and efficiency. Niki learns and becomes smarter as she talks to people! Join the next revolution by being a part of Niki’s foray into voice-controlled commerce!
To test
Once you join the beta community, we’d be really grateful if you could help us with the following tasks:
Try booking a free event using the voice command feature
Ask Niki to find buses from a source to a destination on a particular date
Ask Niki to show you nearby restaurants or ATMs
Try different queries which you would want Niki to help you with
Try asking Niki for offers running on the app
Become a beta user
Provide Feedback
Requirements
4.7 Mb
Android 4.0 and up
Available only in India for now
Updated 19th Jun 2017
Download
Find out more at http://niki.ai
No mirror apk ? Would like to test it but it's not viable in my country
looks great!nice work captain!
xVitja said:
No mirror apk ? Would like to test it but it's not viable in my country
Click to expand...
Click to collapse
Hi, it works only in India for now. Stay tuned for more updates.
New update is out. Voice features are available now in Beta.
{
"lightbox_close": "Close",
"lightbox_next": "Next",
"lightbox_previous": "Previous",
"lightbox_error": "The requested content cannot be loaded. Please try again later.",
"lightbox_start_slideshow": "Start slideshow",
"lightbox_stop_slideshow": "Stop slideshow",
"lightbox_full_screen": "Full screen",
"lightbox_thumbnails": "Thumbnails",
"lightbox_download": "Download",
"lightbox_share": "Share",
"lightbox_zoom": "Zoom",
"lightbox_new_window": "New window",
"lightbox_toggle_sidebar": "Toggle sidebar"
}
Cogxio is a free-for-all Indian dating, matchmaking, relationship, singles dating & hangout app to meet with singles & like-minded people around you in real time who are similar to you in terms of activities, interests and lifestyle. Dating and connecting people or friends around has became instant, easy, safe & secure.
It is an intelligent location based meeting, dating & matchmaking app that heavily focuses on data driven decisions. It does not use swipe approach but instead focuses 'Hyper Locally' and let you communicate instantly with new interesting people & friends. It is a free social dating & matchamking app exclusively for educated & interesting people around you. It is a platform created to provide localized real experience in real life. Cogxio makes online dating easier for real people to connect in real time. This free android dating app and will always be Free. Cogxio is one of the best free android Indian dating app. Cogxio makes online dating & matchmaking simple & instant. This online dating app does not charge anything from anyone as it is always FREE ONLINE DATING APP and will always be FREE DATING APP.
Cogxio has been seen in leading media news papers such as Economic Times, Indian Express, NextBigWhat and more.
---------------------------------------------------------
HERE ARE SOME COOL THINGS ABOUT COGXIO
Verified Profile- You get more matches when you verify your phone number & identity proof.
Conversations - Chat up with your matches on our messenger and express yourself better with our cool selfies or images.
Instant Connect - Get information about what’s common between you and a possible match immediately and decide to take the next step by expressing yourself.
Introduce - Expressing yourself was never so easy. Send “Crush” or “Introduce in 140 characters” yourself privately by the click of a finger on a person’s profile.
Get Matched - If you get a ‘Crush’ back or get your Introduction accepted, you are one step closer to finding that “Special Someone” and then you can start interacting and plan to meet.
Tag Search - You can find similar people using tag search to find out the right match for yourself.
Counselor Help - Connect to our counselor if you have any relationship, personality, health, photography & psychology related issue.
We’re free - Yes! You read it right and we have no place for stupid ads.
---------------------------------------------------------
SAFETY, SECURITY & PRIVACY
Your privacy and safety is our number one priority. Remember, you can always “Report Spam” or “Block” abusive messages or people from reaching out to you.
No 'Randos' only 'REAL PEOPLE'. We guarantee that there are no fake accounts on Cogxio.
And to make this app working good we need all your help. We need testers who can submit bugs at Gmail with the subject as cogxio bug report.
Download
Google Play Store
XDA:DevDB Information
Cogxio, App for all devices (see above for details)
Contributors
DraXonic
Version Information
Status: Testing
Created 2016-06-02
Last Updated 2016-06-02
Reserved
No one to test and help?
{
"lightbox_close": "Close",
"lightbox_next": "Next",
"lightbox_previous": "Previous",
"lightbox_error": "The requested content cannot be loaded. Please try again later.",
"lightbox_start_slideshow": "Start slideshow",
"lightbox_stop_slideshow": "Stop slideshow",
"lightbox_full_screen": "Full screen",
"lightbox_thumbnails": "Thumbnails",
"lightbox_download": "Download",
"lightbox_share": "Share",
"lightbox_zoom": "Zoom",
"lightbox_new_window": "New window",
"lightbox_toggle_sidebar": "Toggle sidebar"
}
What is Car Maintenance?
Car Maintenance is an android application suitable for devices above API level 14 (4.0.3 ICS). It's purpose is to help the user keep track of his car's service history and condition. User needs to fill in basic information about his car, after that he can fill in his service history. Currently it is up to the user to update his car mileage, and based on the given information the application can alert the user when he is due his service on a given element.
The user can also add a separate part to another log (section) which has been changed due to wear or damage.
Information about service supplies/parts can be applied:
Part name.
Factory numbers.
Prices.
Dealers. (where the item was purchased)
Expenses (change cost)
Mileage on which the item was changed.
Next check when item needs to be checked.
Date on which the item was changed.
Next date when item needs to be checked.
Item description can be applied.
Item photograph can be applied.
Local workshop data can be entered.
If a local workshop number is provided, it can be dialed with a single click.
If a local workshop address is provided, it can be viewed on Google Maps or Directions can be provided based on the address.
More...
Data is stored only on your device. No internet connection required.
Download
Facebook Page
Enjoy
Promo codes for the app, now available on the Facebook Page
Get them before they're all taken.
Great idea, I'm sure a lot of people need this app.
Latest update now includes cloud synchronization between devices (BETA) - Version 2.0.2b :good:
Promo codes giveaway now available. Grab a code to remove ads from the app - codes.
It's a nice looking, detailed app, but I would rather have the ability to add more than one vehicle than getting rid of ads. I can track one vehicle maintenance, but the whole reason for an app was to be able to track all three vehicles I own.
eliteva said:
It's a nice looking, detailed app, but I would rather have the ability to add more than one vehicle than getting rid of ads. I can track one vehicle maintenance, but the whole reason for an app was to be able to track all three vehicles I own.
Click to expand...
Click to collapse
Thank you!
You can add more than one vehicle and remove ads as well. Usually you would have to purchase the remove ads option, but you can currently get a promo code from above for the ads and remove them for free. In order to add more cars you would have to subscribe to Premium, you have a free trial as well.
Version 2.1.1 is now available. Added fuel logger.