All Android Phones Vulnerable to Extremely Dangerous Full Device Takeover Attack

froggyboy604

Well-Known Member
Staff member
Manager
Full GL Member
28,675
2007
759
Awards
20
Credits
9,965
Mature Board Viewing
Unlock full profile styling

Researchers have discovered a new attack, dubbed 'Cloak and Dagger', that works against all versions of Android, up to version 7.1.2.

Cloak and Dagger attack allows hackers to silently take full control of your device and steal private data, including keystrokes, chats, device PIN, online account passwords, OTP passcode, and contacts.

Read More

If you need to use a phone at all time, and don't want your important information to be leaked online, it is a good idea to use a land line phone, and regular non-smartphone like a flip phone which maybe less likely to be a victim of similar serious attacks like "Cloak and Dagger" which can take control of Android smartphone without the user noticing.

Other non-Android smartphones may have similar security vulnerabilities which are not yet discovered or fix.
 
This is why I don't do banking/payment via my phone. Limit the devices you want to do that.
 
But how does this "attack" work? Our Smartphone has no data plan, just talk...
 
As with most, it can be avoided by being smart. Only download apps from the play store and try to stay away from unknown games. Just download the main ones from large well known companies.
 
But how does this "attack" work? Our Smartphone has no data plan, just talk...

You, someone else, or an Android app need to manually or automatically install an app or game which is infected with the Cloak and Dagger full device takeover vulnerability installed on it according to the full article. You don't even need to be online. Someone can use an .apk installer file to install the Android app if you set your phone to allow installing .apk files which you downloaded outside of Google Play like the Amazon App store, 1Mobile, Getjar, or file sharing websites like Dropbox and 4Share.

As with most, it can be avoided by being smart. Only download apps from the play store and try to stay away from unknown games. Just download the main ones from large well known companies.

There is always a chance that the App maker's Google app publishing account gets hacked, and a hacker uploads the same app with the Cloak and Dagger vulnerability installed on the newly updated hacked app.

Big companies sometimes have bad employees, or the company becomes bad, and choose to break the law, and use this security vulnerability to steal data, and stalk Android users.

Big App companies can also be working with the government to spy on Android users by using cloak and dagger in their app, or risk getting arrested if they refuse to work with the government to spy on users.

Countries like Syria, and North Korea most likely use cell phone apps and computer programs to spy on people's cell phone, and copy all their private data. Some governments in North America, Europe, and Asia are becoming more restrictive, and are using law enforcement like the police and the internet, computer operating systems, cell phones, and Smart TVs to spy on people's data and privacy. Governments can secretly infect Cloak and Dagger into apps made by big companies, or force big companies to infect their own apps with Cloak and Dagger.
 
Last edited:
I don't download any apps except Instagram and that's about it. :grin:
 
I don't download any apps except Instagram and that's about it. :grin:

There are apps like Calculator, Contacts, Launchers, and Web browsers which come pre-installed on some phones which may secretly have the "Cloak and Dagger" vulnerability which is built-in to a virus infected version of a pre-installed apps on an Android phone. If a user update a pre-install app to a newer version with Cloak and Dagger secretly installed on it, and the new version is made by a hacker which hack the App publisher Android account to publish a infected app, people who install the new app will be infected.

Sometimes, users are tricked into opening a fake video file which is infected with a virus, or opening another fake virus infected file type which can secretly install viruses, spyware, and ransomware onto a smartphone, tablet, and PC without the user knowing, or seeing the install process.
 
Hmm....why is this not more well known? Android has been around for years, yet this is the first I've heard of this. I've never updated any pre-installed app as I don't have the space. lol
 
Hmm....why is this not more well known? Android has been around for years, yet this is the first I've heard of this. I've never updated any pre-installed app as I don't have the space. lol

Most news companies like TV news mainly post tech stories like the WannaCry Ransomware which affect a lot of people, and they are usually limited to an hour or less to tell most of the important news.

Google Android Security problems don't get as much attention on the news, on most technology websites, and regular websites because the stories are not as exciting as news about the latest Nintendo Switch consoles, and 4K TV sets which get more reader.
 
Last edited:
Back
Top