Android malware steals user credentials using optical character recognition

Margot Robbie@lemmy.worldmod to Android@lemmy.world – 51 points –
Android malware steals user credentials using optical character recognition
arstechnica.com
4

You are viewing a single comment

A bunch of malicious crypto apps with hidden malware that overlays over legitimate crypto wallets to steal credentials. Technique looks very sophisticated based on the article's breakdown.

you have to specifically give permission to overlay. I never give overlay permission even to most popular apps.

It seems like they ask for accessibility permissions first, and exploits that to automatically click "accept" and grant itself other permissions, which I assume overlay is one of them.

This dumb shit is why Google keeps crippling the accessibility API more and more. Idiots need to stop clicking on stuff just because the app asks them to.