Hacking a phone might start with an app that looks familiar, or with a window that asks the user to press allow, but behind this simple step, the app might gain access to sensitive parts of the device, from photos and location to the camera, microphone, and messages.
Hot Topics
5 red and purple foods that may help support heart health
A Chinese robot and a Russian robot attack humans Has the rebellion begun?
As malware has evolved, some attacks now rely as much on deceiving the user as on exploiting technical vulnerabilities, to turn an ordinary-looking application into a tool for data collection, espionage, or fraud.
Cybersecurity in mobile phone against scam, hack and fraud. Encrypted smartphone. Password lock. Online data hacker. Cyber scammer using tech for phishing. Safety login app to protect personal privacy
Malicious applications do not always come in the form of clearly dangerous programs. They may be disguised within applications that appear useful, impersonate well-known names and services, or reach the phone through installation files downloaded from sites or links outside of official stores.
Google explains that malware on the Android system includes categories such as Trojan horses, phishing, and spyware, and can target user or device data, or give the attacker the ability to control it or perform remote operations.
The risks increase when installing apps from outside the Google Play app store, so Google Play Security checks the apps on the device, including those installed from sources outside the store, and can warn the user about harmful apps, disable them, or remove them.
Permissions... the shortest path to your data
Malware does not always need to forcibly break into a phone; in some cases, it is enough to convince the user to grant it the permissions it needs.
Phone systems allow apps to request access to sensitive functions and data, such as location, photos, contacts, camera, and microphone. Apple confirms that the user can control these permissions for each app from the privacy and security settings.
The problem becomes even bigger when an application requests permissions that are not related to its primary function. A simple photo editing application, for example, may not have a logical need for constant access to the microphone or messages.
Therefore, the minimum permissions rule is one way to reduce risk, as Google's guidelines for developers indicate the need to use the minimum permissions necessary for the application's functions.
Cybersecurity threat, phishing email scam concept. Man hand on phone, data breach danger. Hacker attack, internet fraud, password stealing. Spam message, virus, security risk warning.
Unreliable sources are one of the channels through which malware can reach a phone (Shutterstock).
When powers become a tool for spying
Once an application is granted permission, seemingly separate data can become parts of a larger picture of the user. Access to location may reveal movements, access to photos and files may expose personal information, while access to messages or notifications may reveal sensitive data or verification codes in some scenarios.
Google classifies phishing apps, for example, as malware when they pretend to be a trusted entity in order to obtain user credentials or payment information and send it to another party.
Some software designed to access and control the device may exploit more sensitive privileges to perform operations on behalf of the user or facilitate an attacker's access to their data.
Google specifically warns against apps that use accessibility services deceptively, as these permissions may grant an app broad control over the device and access to personal and financial information without the user realizing the nature of the risk.
Tags:
technology
