this post was submitted on 10 Sep 2024
141 points (96.1% liked)

Technology

59174 readers
2961 users here now

This is a most excellent place for technology news and articles.


Our Rules


  1. Follow the lemmy.world rules.
  2. Only tech related content.
  3. Be excellent to each another!
  4. Mod approved content bots can post up to 10 articles per day.
  5. Threads asking for personal tech support may be deleted.
  6. Politics threads may be removed.
  7. No memes allowed as posts, OK to post as comments.
  8. Only approved bots from the list below, to ask if your bot can be added please contact us.
  9. Check for duplicates before posting, duplicates may be removed

Approved Bots


founded 1 year ago
MODERATORS
 

cross-posted from: https://lemmy.zip/post/22281366

Optical Character Recognition converts passwords shown in images to machine-readable text.

McAfee blog: https://www.mcafee.com/blogs/other-blogs/mcafee-labs/new-android-spyagent-campaign-steals-crypto-credentials-via-image-recognition/

you are viewing a single comment's thread
view the rest of the comments
[–] [email protected] 23 points 2 months ago (1 children)

There’s no indication that any of the apps were available through Google Play.

So it's just users installing untrusted apps to their phone?

scour infected phones for text messages, contacts, and all stored images

They also can't do that without the user explicitly giving the app permission to do those things, unless they found an exploit or something, but the article doesn't say that.

Also, why would you have images with passwords in them on your phone anyway?

People really should know better nowadays than to do any of this shit. Every step here is preventable by the user just thinking about what they're really doing.

[–] [email protected] 15 points 2 months ago (1 children)

A lot of cryptowallets let the user log in with a randomly generated combination of words. They often ask the user to write those down on paper. However, some people just screenshot that. This malware looks for those combinations specifically.

[–] [email protected] 5 points 2 months ago (1 children)

you mean the seed? i though that should be written on paper, store in a safe, and never on any electronic medium.

[–] [email protected] 9 points 2 months ago* (last edited 2 months ago)

Just like how people should use long unique passwords