APKPure v3.17.18 被植入木马

2021-04-11 14:55:45 +08:00
 az467

If the user has a relatively recent version of the operating system, meaning Android 8 or higher, which doesn’t hand out root permissions willy-nilly, then it loads additional modules for the Triada Trojan. These modules, among other things, can buy premium subscriptions and download other malware.

If the device is older, running Android 6 or 7, and without security updates installed (or in some cases not even released by the vendor), and thus more easily rootable, it could be the xHelper Trojan. Removing this beast is a real challenge; even a factory reset won’t do it. Armed with root access, xHelper lets attackers do almost anything they want on the device.

https://www.kaspersky.com/blog/infected-apkpure/39273/

20956 次点击
所在节点    Android
69 条回复
Dogtler
2021-04-12 08:47:40 +08:00
@Dogtler apkpure
tankren
2021-04-12 08:49:07 +08:00
只用 Apkmirror 下 play 下不了的
RanKaede
2021-04-12 08:51:41 +08:00
这商店安装 apk 前会播放菠菜广告,本来就不怎么正经。
no1xsyzy
2021-04-12 09:20:37 +08:00
@alexkkaa 原来毛子不是欧洲的,懂了
alexkkaa
2021-04-12 09:23:57 +08:00
@no1xsyzy 毛子的风格跟欧美完全两样, 杠精。你说毛子是欧美我还说毛子是东亚。 有意思吗?
mxdzs0612
2021-04-12 09:30:29 +08:00
装了个去广告版的,看了下是 v3.17.17 ,希望别有事……
ReZer0
2021-04-12 09:42:27 +08:00
那么用网页版应该就没问题了吧……我之前一直用网页版下,APP 什么的倒没装。
asche910
2021-04-12 10:01:11 +08:00
有 Play Store 为啥不用?什么,2021 还有不会上 google 的?
skiy
2021-04-12 10:08:48 +08:00
文章说是广告 SDK 内置的,估计是第三方 SDK 的锅。不过不排除 APKPURE 知道这事。
hijoker
2021-04-12 10:47:18 +08:00
卧槽,以前用过。。。
anjianshi
2021-04-12 10:56:50 +08:00
@asche910 我的小米到现在都没成功装上过 play store
xishijt
2021-04-12 11:05:29 +08:00
我就说,怎么 突然 3.17.18 就开始有这么恶心的广告,直接去下载了毛子的去广告版.看样子 apkpure 不能用了
no1xsyzy
2021-04-12 11:06:44 +08:00
@alexkkaa 这只是你的想法吧;真是难为你了
zfatcat
2021-04-12 11:09:31 +08:00
On April 8, we informed APKPure about the issue. On April 9, APKPure representatives replied that they saw the problem and were working on the fix. Shortly after that, a new version (3.17.19) appeared on the APKPure website. According to itsdescription, the update “Fixed a potential security problem, making APKPure safer to use.”
We can confirm that the problem has indeed been fixed: APKPure 3.17.19 doesn’t contain the malicious component. It is safe to use.
How to guard against Trojanized APKPure
文章后半部分好像说修复了,我看了一下好像我装的是 3.17.16 ,点进去他让我更新 19,不更新就用不了,想了一下还是卸载了,心有余悸,幸好之前没更新 18
youbaoer
2021-04-12 11:10:31 +08:00
在用 3.14.1,还行下载时不用看广告
Pogbag
2021-04-12 11:23:14 +08:00
@eggshell 竟然是李自然的,我在油管看过他好多视频
exploreexe
2021-04-12 11:33:30 +08:00
ApkPure 是李自然搞的,很早之前扒过李自然的资料,发现是他做的以后感叹怪不得这老哥知道这么多。
rajab
2021-04-12 11:51:03 +08:00
3.15.1
新版下载时有广告,换老版本了
MaverickLee
2021-04-12 11:54:42 +08:00
@no1xsyzy #44 你问下睾贵的西欧人愿不愿意和斯拉夫毛子一起做欧洲人?(doge)
hs0000t
2021-04-12 12:21:23 +08:00
看了一下,3.17.12 ,一直没更新

这是一个专为移动设备优化的页面(即为了让你能够在 Google 搜索结果里秒开这个页面),如果你希望参与 V2EX 社区的讨论,你可以继续到 V2EX 上打开本讨论主题的完整版本。

https://www.v2ex.com/t/769879

V2EX 是创意工作者们的社区,是一个分享自己正在做的有趣事物、交流想法,可以遇见新朋友甚至新机会的地方。

V2EX is a community of developers, designers and creative people.

© 2021 V2EX