Cybercrime involves computers and networks, and more recently smartphones. Smartphones are so embedded in our daily lives and have become an extension of us. In our selfie culture, the advanced camera and video capabilities of smartphones are popular in capturing special moments in real-time with the click of a button. Therein lies a privacy vulnerability of our data which could, with and without our knowing, be targeted by attackers and cybercriminals.
Devices connected to a network and the Internet may be used in committing a crime, or they may be the targets. Cybercrime involves offences related to hacking, copyright infringement, unwarranted mass-surveillance, sextortion, child pornography, and child grooming. Privacy concerns related to cybercrime is associated with the interception and disclosure of confidential information. Incidences of both governmental and non-state transgressions cybercrimes, including espionage and financial theft have been reported. What is seldom mentioned is that someone can remotely take control of our laptops’ and smartphones’ cameras to spy on us.
Someone can virtually be watching you through your own webcam, but how do they do it? Some of the more common ways that hackers use to gain control of your laptop’s webcam is by using RATs (Remote Administration Tools). A RAT is a program or software that allows a third party to take control of a system in a different location and allow them to operate it. Hackers can install the RATs through services like peer-to-peer sharing platforms.
Another way a hacker may take control is through malicious codes hiding in a web application. Without adequate security, the hacker can take control of a system. Good cybersecurity may help prevent some of these codes and malware from running on your computer. Additionally, botnets can be used to perform distributed denial-of-service attack, steal data, send spam, and allow the attacker to access the device and its connection. If the person controlling a network is a cybercriminal, they can introduce malware into private computers, allowing them to take full control of the computers.
Laptops are not the only devices vulnerable to security issues. More recently, security researchers at Checkmarx have uncovered a vulnerability in the camera apps which are pre-installed on millions of Android devices, known as CVE-2019-2234. The app could allow an attacker to secretly take photos and record videos without the knowledge of the user and hence, without permissions being granted. This may occur even if the phone is locked or the screen turned off, or even during a call. The Checkmarx researchers found that a malicious app could bypass the safety net completely by requesting storage permissions and circumventing the permission policy normally requested. By using exchangeable image file format (EXIF), the metadata embedded within the stolen photos could be used to identify your physical location
The researchers created a rogue and malicious weather app which did not request any special permissions beyond the basic storage access requests, and thus, it did not appear suspicious or threatening to users. The app created a persistent connection back to a remote command-and-control (C&C) server from where an attacker can send it instructions and even closing the app does not terminate the connection.
With the app researchers were able to do were:
- Take a photo on the phone and upload it to a C&C server
- Record a video on the phone and upload it to the C&C server
- Deconstruct the latest photos and look for GPS tags and thus locate the phone on a global map
- Function in stealth mode to take photos and record videos silently
- Automatically record a video and audio from both sides of the conversation when a call was made.
Checkmarx disclosed the vulnerability to Google and Samsung before it was made public and Google issued a patch for the flaw which was distributed to all Android partners. Samsung released a fix, but some Android phones may still be unpatched, and do not have any or the latest security updates installed. The researchers found that the vulnerability did not only impact the Google and Samsung camera, but also impacted camera apps from many other smartphone vendors. That means the vulnerability potentially impacted hundreds of millions of phones.
As general best practices to mitigate threats and vulnerabilities, users are urged to update all applications on their device and protect their devices with the best antivirus software available on the market.
Let us help guide you into which Home Fibre line you should be using!