Infoblox Threat Intel<p>VexTrio User Experience 5/N<br> <br>So what next? Shall we do fake apps? 100% of these experiences come from starting with a compromised site and just allowing all notifications and permissions that are requested. This one came from a notification that the phone needed to be cleaned and it recommended download the app Antivirus toolkit from the Google Play store. What could go wrong? There are over 1M downloads! This scareware fake app was delivered via Monetizer; see the imgur link.<br> <br>Then read the reviews. Like the other fake apps in this genre it doesn't do anything except show ads and gain access to your personal information. We'll share some of the other fake apps in a different post; some of them are quite giggle producing. But unfortunately, they work - people are scammed out of tons of money through these jerks.<br> <br>Once installed, the app tells you that your browser is compromised, and you need to install a secure browser -- another one on the Google store with lots of downloads and seemingly good reviews. But finding the real reviews shows the same behavior… lots of ads and access to personal data.<br> <br>I haven't tried to do any sandboxing or reverse engineering of these apps that the VexTrio affiliates are recommending; I'm just getting the full user experience.<br> <br>In the meantime, the Antivirus Toolkit continues to push notifications including that is has instaled (sic) and uninstaled (sic) Chrome for me.</p><p>video of the virus app is here. only defanged as i maxed the image load for mastodon.<br>https://imgur[.]com/a/bxPEyhB<br> <br><a href="https://infosec.exchange/tags/dns" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>dns</span></a> <a href="https://infosec.exchange/tags/threatintel" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>threatintel</span></a> <a href="https://infosec.exchange/tags/fakeapp" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>fakeapp</span></a> <a href="https://infosec.exchange/tags/scam" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>scam</span></a> <a href="https://infosec.exchange/tags/scareware" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>scareware</span></a> <a href="https://infosec.exchange/tags/phishing" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>phishing</span></a> <a href="https://infosec.exchange/tags/vextrio" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>vextrio</span></a> <a href="https://infosec.exchange/tags/cybercrime" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>cybercrime</span></a> <a href="https://infosec.exchange/tags/cybersecurity" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>cybersecurity</span></a> <a href="https://infosec.exchange/tags/infosec" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>infosec</span></a> <a href="https://infosec.exchange/tags/infoblox" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>infoblox</span></a> <a href="https://infosec.exchange/tags/infobloxthreatintel" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>infobloxthreatintel</span></a></p>