The Certifi-Gate vulnerability for Android was found by Check Point security researchers in an app available on the Google Play App Store.
The vulnerability, which allows an attacker to take remote control over an Android device using its mobile Remote Support Tools (mRSTs), can be exploited using support applications from vendors such as AnySupport, CommuniTake, RSupport, and TeamViewer.
Check Point, the security company that found this bug and presented it at the Black Hat USA 2015 conference in Las Vegas, also released a scanner app that scans an Android phone and reports whether the phone is vulnerable to the Certifi-Gate bug.
This scanner already has 50,000 to 100,000 installations and includes a phone system that reports its results to Check Point staff.
According to the security team that has grouped all the data, 15.84% of scanned smartphones have been found to have a vulnerable plugin (from those listed above) installed on the user's phone.
Additionally, 42.09% of phones were also vulnerable, but without having any application with a vulnerable plugin installed on the device.
0.01% of scanned phones, which represents 3 phones, were found to be actively exploited by vulnerabilities.
Taking a closer look at the infected phones, Check Point staff identified the Recordable Activator Android app, an app distributed through the official Google Play Store, as the culprit.
The app has been downloaded between 100,000 and 500,000 times, although it has since been removed from Google Play.
The application is a simple screen recording like many similar applications and worked with four methods of recording the user's screen: via USB, via Android 5 display, via the root user, and via the TeamViewer plugin.
According to Check Point researchers, "the Recordable Activator application bypasses the Android device's permission to use the TeamViewer plugin to gain system-level access and record the device's screen.".
According to The Register, the developers of the vulnerability, a British company called Invisibility Ltd, say that "the recording feature is primarily used by games that require recording to upload their gameplay to YouTube. Hundreds of thousands of children use this feature to upload their gameplay to their YouTube channel.".
The "Recordable Activator application was used by older versions of the TeamViewer plugin in exactly the same way. It did this in response to a user request ... and informed the user in the same way that TeamViewer did it," said Christopher Fraser, a spokesman for Invisibility Ltd.
The application does not appear to have exploited a user's private information for its own benefit, but it appears to have used the Certifi-gate vulnerability to enhance its own capabilities, without informing and scaring users with pop-ups that would mention privacy protection.
Looking at Check Point's data collected by their scanner app, we also see that LG devices were the most vulnerable, followed by Samsung and HTC.
The three phones actively used by the vulnerability are Samsungs, but according to the chart, LGs generally appear more vulnerable to Certifi-gate.
Sony devices appear to be the least vulnerable of all the scanned brands.
Source: secnewsgr.kinsta.cloud



