Android malware devs are already bypassing a new “Restricted Setting” security feature that Google introduced in Android 13.
Android 13 was released this week, with the new operating system rolling out to Google Pixel and the source code published to AOSP.
As part of this release, Google attempted to cripple malware for Android phones that attempted to exploit powerful Android permissions, such as the Accessibility Service, to perform malicious behavior in the background.
However, Threat Fabric analysts say today that malware creators are already developing Android malware droppers that can bypass these restrictions and deliver payloads that enjoy high privileges to a user's device.
In previous versions of Android, most mobile malware found its way onto millions of devices via dropper apps available on the Play Store, which disguised themselves as legitimate apps.

Upon installation, Android malware apps prompt users to grant access to dangerous permissions and then load malicious payloads by abusing the Accessibility Service.
The Accessibility Service is a massively abused accessibility system on Android that allows apps to perform swipes and taps and go back or return to the home screen, all without the user's knowledge or permission.
Typically, Android malware uses the service to grant itself additional permissions and stop the victim from manually deleting the malicious app.
In Android 13 , Google security engineers introduced a “Restricted Setting ” feature, which blocks apps from requesting Accessibility Service privileges, limiting the feature to only accept APKs that come from Google Play .
See also: 9 Signs that your PC is infected with spyware
However, researchers at Threat Fabric were able to create a proof-of-concept dropper that easily bypassed this new security feature to gain access to the Accessibility Service.
In a new report released today, Threat Fabric discovered a new Android malware dropper that is already adding new capabilities to bypass the new Restricted Setting security feature.

While monitoring Xenomorph Android malware campaigns , Threat Fabric discovered a new dropper that is still under development. This dropper has been dubbed “BugDrop” due to the many flaws that plague its operation in this early phase.
This new Android malware dropper has code similar to Brox, a freely distributed malware development tutorial circulating on hacker forums, but with a modification to a string in the installer function.
"What caught our attention was the presence in the Smali code of the string com.example.android.apis.content.SESSION_API_PACKAGE_INSTALLED," Threat Fabric explains in the report.
"This string, which is not present in the original Brox code, corresponds to the action required by the intents to create a per-session setup process."
Third-party apps have two methods for installing other apps. The first and most common is the non-session-based, which essentially hands off installing a single APK file to the system package installer.
The second is the session-based installation method , which allows apps to schedule the installation of one or more APKs at a time . It is commonly used by apps on the Play Store and allows for the installation of multiple APKs in one go, with apps distributed as a single “base” APK and multiple “split” APKs.

In Android 13, Google decided to restrict access to Accessibility Service and Notification Listener, two highly privileged APIs, only to apps that use the session-based installation method.
See also: Facebook Messenger: Are your messages secure?
Applications loaded via the session-based installation method will not see the Restricted Setting and, therefore, users can enable the Accessibility Service and/or Notification Listener.
If malware droppers like BugDrop use this installation method to load the malware payload, Android 13 recognizes the use of the API and does not enforce the restriction.
“When fully implemented, this slight modification will completely bypass Google’s new security measures, even before they are effectively implemented,” Threat Fabric comments.
BugDrop is another ongoing project by a group of malware creators and operators called "Hakoden", who are also responsible for creating the Gymdrop dropper and the Xenomorph Android banking trojan.
When BugDrop is ready for mass deployment, it is expected to be used in Xenomorph campaigns, allowing credential theft on the latest Android devices.
Additionally, the latest Xenomorph samples analyzed by Threat Fabric have added remote access trojan (RAT) modules, making the malware an even more potent threat.
Source: bleepingcomputer.com
