mysk, (edited )

The rogue 2FA app that steals scanned secrets is now ranked 18 on the German App Store for the productivity category. No wonder! The app disguises as a Microsoft app. It is the top hit when you search for "Microsoft Authenticator" and the developer has updated the screenshots in the ad card to highlight the word "Microsoft". Surprisingly, the product page of the app shows different screenshots with the word "Microsoft" removed.
The app now has 1.2K reviews, as opposed to 18 when we first addressed the app.

🙏 Boosting this post will help spread the word. Thank you!

skry,
@skry@mastodon.social avatar

@mysk I wonder if it’s possible to report this to , who could alert through legal channels. It’s ridiculous that Apple can’t take down a reported, malicious app. Some press might help too.

vncntx,

@mysk This is extremely disappointing from Apple. The whole justification for their 30% global tax is so they can maintain systems and procedures to prevent apps like this from going on the store.

wonka,
@wonka@chaos.social avatar

Ich nehme mal an, @jiska hat davon schon gehört?

@mysk

ElSupreme,

@mysk

Apple profiting mighty off of this fraud. [ad] tag on those hits.

dammitjanet,
@dammitjanet@mastodon.social avatar

@mysk gosh. I wonder what would happen if a spam phishing email came in like this?

dammitjanet,
@dammitjanet@mastodon.social avatar
wraptile,
@wraptile@fosstodon.org avatar

@mysk apple fanboys be like "but walled gardens keep us safe" and news like this pop up every month lol

kkarhan,

@mysk let me guess: #Google doesn't give any f**ks?

Shit like that would not fly on @fdroidorg - in fact they'd rather yeet apps having including security issues.

RPBook,
@RPBook@historians.social avatar

@kkarhan @mysk @fdroidorg it's in the Apple app store, so I suspect Google doesn't care about it, no.

theandil,

@mysk 😳

reza,

@mysk Wait, 1.2K reviews have also been removed?

iBleedIn6Colors,

@mysk According to the Apps privacy section its App Store Page they are WAY BETTER than the original! Microsoft’s App sucks up everything including all of your content, even your location. I would never use either app!

nowherefast,
@nowherefast@techhub.social avatar

@mysk hope someone takes this to a EU hearing when Apple tries to bullshit politicians into believing their walled garden is anything else then a bloody monopoly.

eljefedsecurit,

@mysk it's an apple store app, did you report it to apple yet?

mysk,

Just tested the latest version and it still sends scanned secrets to the developer's remote server (Version 1.10.1). Meanwhile, the app has climbed to no. 13 on the German App Store 😳

jak2k,
@jak2k@mastodontech.de avatar

@mysk
That's why I use android and f-droid.

JetForMe,
@JetForMe@geekstodon.com avatar

@mysk is there a way to report an app to apple?

mysk,

@JetForMe Yes, but you must download the app first. Then, an option to report the app appears in the information section of the app in the App Store, more here:

https://beebom.com/how-report-bad-apps-scams-app-store-iphone/

feld,
@feld@bikeshed.party avatar

deleted_by_author

  • Loading...
  • mysk,

    @feld
    Read the text in the screenshots it includes in the ad. And when you search for "Google Authenticator", it uses screenshots with text suggesting it is a Google app. Also check this video out:

    https://defcon.social/@mysk/110576091858818294

    dgoldsmith,
    @dgoldsmith@mastodon.social avatar

    @mysk Did you report this app via: https://reportaproblem.apple.com ? That link is for stuff you've already purchased, but you can also tap "Report a problem" directly in the app store page.

    mysk,

    @dgoldsmith Yes, and many other users reported it, too.

    dgoldsmith,
    @dgoldsmith@mastodon.social avatar

    @mysk Thanks!

    casmael,

    @mysk lmao fuck 2fa man

    Yurgo,
    @Yurgo@mastodon.social avatar

    @mysk Oh dear, wonder if there are people so stupid to pay for such app. Those would need some kind of protection indeed.

    Geoffairey,
    @Geoffairey@mastodon.social avatar

    @mysk Apple Search Ads failing spectacularly

    teezeh,
    @teezeh@digitalcourage.social avatar

    @mysk Form my point of view, this is a non-issue. It is really easy to correctly discover and identify the real Microsoft Authenticator published by Microsoft Corporation. People who download this rogue app will fall victim to any other scam as well.

    mysk,

    @teezeh This's very easy to say if you're knowledgeable about IT. But many people aren't. I tested this with multiple persons. They all picked the first app because it's highlighted and also because the screenshot says "Microsoft"

    teezeh,
    @teezeh@digitalcourage.social avatar

    @mysk I know. That's why I wrote that they woul fall victim to any other scam as well. Sure, I would prefer serious curation in app stores. But pretty much all of them prefer quantity over quality. The Microsoft Store is the worst IMHO ...

    aw,

    @mysk And this is why Apple takes their 30% right? To keep its users safe... Scandalous how Apple doesn't even seem to be trying. Any app that goes high on the popularity charts should get extra scrutiny for scamminess/scumminess.

    jramskov,
    @jramskov@helvede.net avatar

    @mysk So much for the secure, curated Apple App store #Apple

    guiltmanager,

    @johnnyd_cm @mysk how the hell did it gget into the apple app store in the first place, apple are supposed to be control frieks when it comes to allowing apps. then again they dont stop apps that are completely inaccessible with voiceover so...

    fujiwara,
    @fujiwara@sakurajima.moe avatar

    @mysk I've seen more than one person at my work with this app on their phone. I've tried to warn people about it, but they just won't listen.

  • All
  • Subscribed
  • Moderated
  • Favorites
  • privacy
  • DreamBathrooms
  • everett
  • InstantRegret
  • magazineikmin
  • thenastyranch
  • rosin
  • GTA5RPClips
  • Durango
  • Youngstown
  • slotface
  • khanakhh
  • kavyap
  • ngwrru68w68
  • tacticalgear
  • JUstTest
  • osvaldo12
  • tester
  • cubers
  • cisconetworking
  • mdbf
  • ethstaker
  • modclub
  • Leos
  • anitta
  • normalnudes
  • megavids
  • provamag3
  • lostlight
  • All magazines