this post was submitted on 31 May 2024
90 points (97.9% liked)
Cybersecurity
5743 readers
118 users here now
c/cybersecurity is a community centered on the cybersecurity and information security profession. You can come here to discuss news, post something interesting, or just chat with others.
THE RULES
Instance Rules
- Be respectful. Everyone should feel welcome here.
- No bigotry - including racism, sexism, ableism, homophobia, transphobia, or xenophobia.
- No Ads / Spamming.
- No pornography.
Community Rules
- Idk, keep it semi-professional?
- Nothing illegal. We're all ethical here.
- Rules will be added/redefined as necessary.
If you ask someone to hack your "friends" socials you're just going to get banned so don't do that.
Learn about hacking
Other security-related communities [email protected] [email protected] [email protected] [email protected] [email protected] [email protected] [email protected]
Notable mention to [email protected]
founded 1 year ago
MODERATORS
you are viewing a single comment's thread
view the rest of the comments
view the rest of the comments
Only exploits that require human intervention would be defeated by this though. If you have a zero touch exploit that can privesc, the persistance doesnt need to be anything special, you can just wrap your exploit in an ordinary android app and request it be woken up on next boot.
Not necessarily true. It could be a buffer overflow in text message processing, it's still requires a text message to be sent to the phone.
It could be a Wi-Fi or Bluetooth exploit, which requires locality.
It could be a browser, webview, certificate exploit that requires a sophisticated chain of events with a low probability to intercept a web page and get the user to do something that isn't guaranteed.
The exploit might display itself to a user on the phone, so every time it's applied there's a risk of discovery.
Not to mention many advanced persistent threats do not want their exploits to be analyzed, so they will not leave them sitting around to be collected, just waiting for the device to need a reinfection. That's valuable signals capability that you give to your adversary they just need to analyze it.
Those all are things that require external human intervention though?
If the malware is persistent, then one way or another it needs to leave an exploit on the device, it can either be a persistance exploit, or a privesc exploit.
Right so the issue here is we are saying for the class of malware that is not persistent restarting the device will take it out of memory. Which is a strict positive
Yup. Although i'm not sure there are many (any?) malwares that don't have some form of persistence. Exploits requiring human intervention are usually just the first stage, and persistance is the second.
I dont know of any APTs that are purely memory only, but if you know of one please link so I can read up on it.
https://www.youtube.com/watch?v=1f6YyH62jFE
Here is an alternative Piped link(s):
https://www.piped.video/watch?v=1f6YyH62jFE
Piped is a privacy-respecting open-source alternative frontend to YouTube.
I'm open-source; check me out at GitHub.