[02:52.840 --> 02:55.360] Folks, once again, welcome to A New HOPE. [02:56.420 --> 03:02.760] This is about the time of day, it's healthy to remind folks about the 3-2-1 rule, which can help you optimize your con enjoyment. [03:03.900 --> 03:07.360] Three hours of sleep, two good meals, one shower. [03:07.760 --> 03:13.820] Or, on a day like today, three quarts of water, two liters of water, and then, like, some other bottle of water, too. [03:15.960 --> 03:17.240] On to our next speaker. [03:18.420 --> 03:30.500] On the surface, a popular social media app downloaded through the Google Play Store or a piece of malware sideloaded onto a device may look very different, but none of us are here to look at the surface of things. [03:31.400 --> 03:44.160] Our speaker, Bill Budington, will explain perspective as a reverse engineer and an analyst at Android Drafts to see exactly how these are different, how they're the same. [03:49.300 --> 03:49.780] Hey, everyone. [03:50.120 --> 03:51.320] Thanks so much for coming. [03:52.300 --> 03:59.000] I'm going to just let you give your Q&A or the questions at the end. [03:59.820 --> 04:04.040] And I can't really see people, so hopefully I can see Ray's hands at some point. [04:04.580 --> 04:07.840] But, yeah, let me go into presenter mode real quick. [04:09.920 --> 04:11.100] If I can see that. [04:12.460 --> 04:14.000] So I can... [04:15.780 --> 04:16.680] Presenter view. [04:17.380 --> 04:18.220] Bring that over here. [04:22.280 --> 04:22.800] Awesome. [04:24.280 --> 04:26.380] And then, full screen this. [04:30.520 --> 04:42.180] So hopefully you are here to learn about reversing some Android malware or doing some kind of privacy or security audit of apps. [04:42.280 --> 04:47.980] And that's what I've been involved in in maybe the last, you know, year or so. [04:48.320 --> 04:49.860] So I'm pretty new at it, actually. [04:50.080 --> 04:54.500] But I have been looking at some interesting things over the past year. [04:54.500 --> 04:57.280] So I just wanted to kind of run through those. [04:58.500 --> 05:01.420] First, I wanted to mention, like, who are we? [05:01.680 --> 05:02.730] What is EFF? [05:03.480 --> 05:08.100] And EFF is a 501c3 nonprofit. [05:08.940 --> 05:11.680] And we're based in the San Francisco Bay Area. [05:16.600 --> 05:25.560] And we, you know, comprise this kind of triforce of activists, lawyers, and technologists. [05:26.710 --> 05:30.800] And what, you know, I'm part of the technologists team at EFF. [05:31.100 --> 05:36.480] And I kind of look at, you know, various pieces of software, you know, write software. [05:36.480 --> 05:42.440] We have lawyers that defend your digital liberties as you go online. [05:42.780 --> 05:49.120] And, you know, make sure that if you're a security researcher, you don't wind up getting arrested for your security research. [05:50.800 --> 06:01.800] And our fantastic team of activists advocate for you and for a better kind of digital landscape in terms of legal landscape. [06:02.740 --> 06:06.480] So we fight for encryption, privacy, and the security on the Internet. [06:07.860 --> 06:10.300] One second, I'm kind of... [06:17.850 --> 06:18.350] Sorry. [06:20.350 --> 06:21.230] There we go. [06:23.850 --> 06:25.850] And you can find us at EFF.org. [06:28.150 --> 06:30.650] So who am I and why should you listen to me? [06:30.830 --> 06:34.130] First of all, I want to give a huge credit to the person that did this caricature. [06:34.370 --> 06:35.870] I got it at Infosec Southwest. [06:36.630 --> 06:39.630] And, like, every single person that's seen it's like, oh, my God, that's so you. [06:40.070 --> 06:40.710] I'm like, yeah. [06:41.530 --> 06:42.250] I can see it. [06:42.310 --> 06:42.770] I can see it. [06:44.010 --> 06:47.010] I'm a senior staff technologist at Electronic Frontier Foundation. [06:48.190 --> 06:52.990] I have been the lead coder for HTTPS Everywhere. [06:53.890 --> 07:07.450] And Panopticlic, which was recently rebranded to cover your tracks, which is something that looks at your browser fingerprint and kind of figures out how identifiable you are based on your browser fingerprint. [07:08.730 --> 07:20.990] As I said, I'm a privacy and security auditor of things like purportedly legitimate apps, as well as reverse engineering and malware in the Android ecosystem. [07:23.290 --> 07:26.830] So why study Android apps in the first place? [07:27.030 --> 07:29.330] Why is that something that is interesting? [07:30.390 --> 07:35.130] Well, I have a familiarity with the Android activity lifecycle myself. [07:35.130 --> 07:57.250] You know, I have also coded in different Android apps and familiarity with Java, which is coded in and more recently kind of a Java derivative called Kotlin, which specifically Android is, you know, coded in. [07:57.430 --> 08:03.970] It's also relatively easy to retrieve Android apps and, you know, have them downloaded. [08:05.570 --> 08:09.070] There's a lot of malware out there in the Android ecosystem to work with. [08:13.450 --> 08:20.990] So I'm just going to give you a high-level overview of Android apps and what that kind of system looks like. [08:21.790 --> 08:25.910] So firstly, you'll see something a lot in this talk, and that's called the APK. [08:25.910 --> 08:27.570] That's an Android package. [08:28.430 --> 08:34.470] An APK is actually just a zip file, an especially formatted zip file. [08:34.590 --> 08:40.910] So if you unzip it, you'll see a lot of files that are just, you know, standard archive files. [08:42.050 --> 08:58.750] Like, if you, you know, unzip an Android APK, you'll see an Android manifest.xml file, as well as various assets that will be included in any Android package that allow that package to function. [09:01.030 --> 09:09.130] And there's also a different standard called a split APK, which is a publication standard. [09:09.130 --> 09:16.470] So you won't download it to your device, but you'll, you know, have it published on the Google Play Store. [09:16.470 --> 09:29.730] And that will split your APK into various different, you know, kind of sub, or various different APKs, depending on your locale or device or DPI. [09:30.750 --> 09:37.450] You can add that kind of configuration will, you know, kind of differ what APK you get. [09:40.980 --> 09:50.080] So there's also other standards that are, you know, not, you know, specifically supported out of the box. [09:50.360 --> 09:57.740] There's an APK, or APK Pure, which is an Android mirror. [09:58.040 --> 10:05.660] Android Google Play mirror has its own package standard called an Android Package Bundle, or XAPK. [10:05.660 --> 10:16.940] And that also, you can get basically this app, a specific app that has its own installer to install this specific type of Android package. [10:20.480 --> 10:27.180] So there's various different app marketplaces that you can find Android APKs on. [10:27.600 --> 10:32.080] Of course, by Envar, the most popular one is the Google Play Store. [10:33.200 --> 10:44.060] And, you know, that's where 99% of people get their packages from, because that's the default publication platform for APKs. [10:44.280 --> 10:52.360] There's also, you know, Google Play Store mirrors, like APK Pure that I just mentioned, and APK Mirror. [10:53.520 --> 11:05.420] Some of these are, you know, maybe clones of the Google Play Store, but their own publication methods allow for infection. [11:05.900 --> 11:14.200] For instance, you know, in APK Pure, their APK Pure app, their downloader app, was infected with malware itself. [11:14.200 --> 11:18.980] So there's some dangers to using third-party marketplaces. [11:21.800 --> 11:24.180] There's also things like F-Droid. [11:24.340 --> 11:34.600] F-Droid is an open source, free and open source marketplace for Android apps. [11:34.600 --> 11:39.300] And there's a number of... Actually, F-Droid is also a standard, too. [11:39.580 --> 11:52.960] So you have an F-Droid package repository index, and that method of verification of that package index can be published by, you know, F-Droid, but it can be published by a number of third parties. [11:53.240 --> 11:59.480] And so you see F-Droid has this kind of master repository, but there's also, you know, for instance, the Guardian project. [11:59.480 --> 12:02.860] They have their own F-Droid third-party repository. [12:03.180 --> 12:05.920] There's actually also F-Droid mirror... [12:05.920 --> 12:09.040] The F-Droid canonical repo also has mirrors. [12:09.320 --> 12:16.660] So it's a little bit confusing, but they all use this kind of standardized way to publish APKs. [12:17.340 --> 12:28.900] You know, F-Droid doesn't, as of yet, support AAB or Android package bundles, but that's, you know, just another way to get Android packages. [12:28.900 --> 12:35.180] And finally, there is the Huawei app gallery, which is very popular in China. [12:36.880 --> 12:52.540] Interestingly, I recently discovered that if you have two exact same versions of the same package, you look at the app manifests of these different packages, and they'll come with different permissions on the app gallery and different signatures. [12:53.580 --> 12:56.140] So that's interesting. [12:56.400 --> 12:59.060] Some of them are very Huawei-specific permissions. [12:59.440 --> 13:13.160] So if you are interested in looking and investigating that avenue of, you know, publishing apps, then please talk to me and I'd be happy to work with you on it. [13:15.020 --> 13:19.840] So all these are different marketplaces, and they have different guidelines. [13:20.360 --> 13:23.680] The Google Play Store has its own terms of service. [13:24.560 --> 13:45.280] They only allow apps that are under 100 megabytes of download, but they also allow you to upload .obb files, cache files, which are, like, for video games that are 1,000 or, like, 900 megabytes or whatever. [13:46.000 --> 13:56.340] You'll have the main APK file, and then it'll load a cache file into the runtime to run the game. [13:57.180 --> 13:58.720] A lot of apps do this. [13:58.900 --> 14:02.480] Just any app that needs more than 100 megabytes to operate. [14:04.480 --> 14:08.120] AppDroid has its own marketplace guidelines, of course. [14:08.320 --> 14:10.080] As I mentioned, it's free and open source. [14:10.080 --> 14:24.060] They also have this, you know, really stringent reliability requirement so that, you know, the apps that are built with their built system, you know, are going to reliably produce the same binary. [14:25.500 --> 14:30.100] And that's a great assurance of the security of FDroid apps. [14:30.920 --> 14:39.020] But that's not necessarily the same way that any given FDroid third party will operate. [14:39.280 --> 14:43.680] So don't trust just because it's using the FDroid protocol to publish their apps doesn't mean it's... [14:43.680 --> 14:46.800] I'm talking about specifically the FDroid canonical repo. [14:48.360 --> 14:54.220] Finally, we developed something at EFF called AP Keep. [14:54.740 --> 15:12.700] And this is a piece of software that pretty much supports all of the things that I've mentioned into one command line application for, you know, using this in a script or downloading apps from various places. [15:13.840 --> 15:18.760] It doesn't support APK mirror, but everything else I mentioned it supports. [15:20.040 --> 15:22.420] So it's a command line tool, as I mentioned. [15:23.740 --> 15:28.710] And it allows batch downloading of different apps. [15:28.700 --> 15:37.520] So you can provide it a CSV and, you know, say, I want to download this column of the CSV. [15:38.400 --> 15:40.340] And each one of these is an app ID. [15:40.800 --> 15:43.260] And it'll just go and download the entire thing. [15:43.860 --> 15:47.320] Of course, there's some throttling mechanisms at play sometimes. [15:48.520 --> 15:51.820] So, you know, you can download apps in parallel with it. [15:52.840 --> 15:57.480] But you can also introduce a delay between each download. [15:58.420 --> 16:02.420] So you don't get throttled by, say, the Google Play Store. [16:06.300 --> 16:08.840] It's also written in asynchronous Rust. [16:09.940 --> 16:14.020] And it prioritizes memory safety, thread safety, and speed. [16:14.020 --> 16:17.140] So it's a really good tool. [16:17.280 --> 16:18.580] And I think you all should use it. [16:20.120 --> 16:22.240] Just, you know, just my bias opinion. [16:23.560 --> 16:24.740] I wrote it, by the way. [16:27.780 --> 16:31.700] So just a kind of quick note on the Android activity lifecycle. [16:32.600 --> 16:33.660] Here's a kind of diagram. [16:33.820 --> 16:34.840] I'm not sure if you could see that. [16:34.960 --> 16:36.860] If we could maybe bring that up full screen. [16:37.640 --> 16:41.780] So there's various kind of stages of an Android app. [16:41.940 --> 16:47.180] And on any given point in time, then you'll be, you know, a pause process. [16:47.580 --> 17:00.280] Or, you know, you have a recreate kind of method that's provided for, you know, an app when it's at a certain stage in its lifecycle. [17:05.220 --> 17:08.940] So kind of getting into, like, analyzing app behavior. [17:09.440 --> 17:11.220] And how do we go about that? [17:11.920 --> 17:13.280] Well, there's two ways. [17:13.460 --> 17:17.700] I mean, and this kind of mirrors doing analysis on apps in general. [17:18.020 --> 17:20.080] And not necessarily just Android apps. [17:20.240 --> 17:23.140] But you can use static analysis. [17:23.140 --> 17:26.380] And that involves downloading the app. [17:26.520 --> 17:27.320] Having it locally. [17:28.200 --> 17:30.160] And inspecting the app files. [17:31.020 --> 17:32.660] Seeing, you know, the... [17:32.660 --> 17:34.620] Looking at the Android manifest file. [17:35.820 --> 17:37.660] Reversing the code. [17:37.920 --> 17:41.540] Either by decompilation or disassembly. [17:42.220 --> 17:43.260] And this is called... [17:43.260 --> 17:45.160] This process is called backsmalling. [17:47.080 --> 17:52.780] Because the Dalvik bytecode representation is called smally. [17:53.400 --> 17:56.380] So it's, like, backing it into smally code. [17:56.880 --> 17:58.780] At least that's what I think of it as. [17:58.860 --> 18:01.380] I'm not sure if that's the actual etymology, but... [18:01.940 --> 18:05.340] And then there's, you know, dynamic code analysis, right? [18:05.640 --> 18:07.420] So there's downloading the app. [18:07.940 --> 18:08.720] Installing it. [18:08.900 --> 18:09.980] And seeing what it does. [18:10.140 --> 18:11.580] Observing the behavior of an app. [18:12.260 --> 18:14.360] And you can do that in various ways. [18:15.340 --> 18:18.940] You know, you can look at the syscalls that it performs. [18:19.240 --> 18:22.460] You can look at the, you know, logs, the system logs. [18:23.780 --> 18:27.400] But, yeah, you should probably use a sandbox if it's malicious code. [18:30.340 --> 18:39.640] And, you know, although, like, from a reverser's perspective, you know, a piece of malware might seem like a legitimate app... [18:39.640 --> 18:47.480] Or, sorry, a piece of malware and a legitimate app on the Play Store, you can download, you know, through legitimate means, may seem different. [18:47.820 --> 18:52.740] But from an analytical, you know, perspective, it's just the same. [18:53.020 --> 18:58.700] It's, you know, looking at the behavior of an app using various tools. [19:00.280 --> 19:11.980] And, yeah, you should use a sandbox if you're analyzing malware, because it's not safe to do so, you know, on just your regular device. [19:14.710 --> 19:20.050] So, firstly, we'll kind of run through an analysis, right? [19:20.230 --> 19:35.150] Like, looking at the AndroidManifest.xml file, which is a top-level file that's available in any package, that will, you know, define what permissions an app is allowed to, you know, access. [19:36.190 --> 19:42.370] It'll define different pieces of hardware that that app can use. [19:44.030 --> 19:49.410] Services, and it'll also define the list of provided activities or screens. [19:49.970 --> 19:55.430] Activities and screens are just kind of semi-the same concept within Android. [19:56.590 --> 20:05.550] So, different activities will be defined, and those activities will have an ID of their own, and only those activities can be run by the app. [20:08.130 --> 20:15.330] So, this is super-tiny text, but this is the app manifest of the Instagram app. [20:16.170 --> 20:25.170] And you'll see, you know, various permissions that it's allowed to use, and different screens, and so on. [20:25.170 --> 20:36.370] You know, it'll even have... this was not one that was provided by the Huawei app gallery, but there's a Huawei-specific permission in there as well. [20:36.530 --> 20:38.370] This was one that was downloaded from Google Play. [20:40.950 --> 20:46.730] So, using static analysis, we can use this tool called JDX. [20:47.370 --> 20:49.230] I think it's pronounced JDX. [20:50.310 --> 20:52.490] It's a decompilation tool. [20:52.710 --> 20:58.370] So, it turns an APK into the Java that... [20:58.370 --> 21:02.370] an approximation of the Java that it was actually written in the first place. [21:02.970 --> 21:05.650] Of course, this sum is lost in translation, right? [21:06.050 --> 21:08.410] You're not going to... if you've, you know, reversed... [21:08.410 --> 21:18.690] or you have, you know, debugging symbols that have been stripped from a binary, you're not going to have, you know, the same names of things as you had in the original code. [21:19.390 --> 21:22.650] But it turns it into something pretty readable. [21:23.170 --> 21:25.890] So, the cons is that it's error-prone. [21:25.890 --> 21:36.230] You'll have a lot of times where there's pieces of the code that can't be decompiled back into the original Java. [21:36.590 --> 21:39.090] So, that's one big con. [21:39.650 --> 21:47.630] It also can't be recompiled back into the APK once you've changed and modified aspects of that app. [21:49.070 --> 21:51.970] Pros, it's actually readable, as I said before. [21:52.830 --> 21:55.030] We'll give an example here. [21:55.030 --> 21:59.470] And this is an example of a piece of malware that I looked at a few months ago. [22:00.150 --> 22:05.450] And you can see, like, stop Tor, and update status, and is Tor disconnected? [22:06.010 --> 22:08.630] These are, like, you can actually follow the code somewhat. [22:08.830 --> 22:14.090] And a lot of it is jumbled, but you can kind of get the general gist of things just by looking at it. [22:17.700 --> 22:20.610] Here's an example of, you know, how it's error-prone. [22:20.610 --> 22:25.480] There's these huge code blocks that are commented out because it just says it straight up. [22:25.700 --> 22:28.550] Jdex couldn't decompile this. [22:28.740 --> 22:29.540] Had some trouble. [22:30.160 --> 22:33.700] Here's what the original Dalvik bitcode looks like. [22:37.120 --> 22:42.020] So there's other tools that are equally as useful in static analysis. [22:42.600 --> 22:44.480] One is called APKTool. [22:45.480 --> 22:52.600] This is a tool which reverses Android into its Dalvik bitcode equivalent, Smully. [22:53.420 --> 22:56.180] It's a representation of that bitcode. [22:57.240 --> 23:18.680] And some of the pros of using something like APKTool space D, which, you know, reverses it, which D unpacks it, is an extremely accurate representation of the original bitcode that is contained in the APK. [23:19.500 --> 23:27.200] And it can be rebuilt, always, unless you've, you know, introduced a coding error or something. [23:27.780 --> 23:30.120] It can be... or a syntax error, I should say. [23:30.340 --> 23:33.220] It can be rebuilt into a running APK again. [23:36.600 --> 23:37.200] Oops. [23:37.640 --> 23:38.200] Cons. [23:39.460 --> 23:41.100] It's nearly unreadable. [23:42.400 --> 23:48.060] You don't want to look at something like this if you're trying to figure out what it's actually doing. [23:48.900 --> 23:53.040] It's not really something that you... it's an enjoyable place to be in. [23:55.260 --> 24:02.500] But you can use these two tools in combination to do some really interesting things. [24:06.420 --> 24:19.600] So, if you want to figure out what a piece of code is doing, then the methodology is to first use jadex to identify an interesting piece, an interesting, you know, place in the code where you want to look deeper. [24:21.220 --> 24:25.980] And then identify where that same place is in the Smalley code. [24:26.180 --> 24:36.240] So, the file structure will be roughly similar when you decompile using jadex or back Smalley using APKTool. [24:37.140 --> 24:47.560] And so, you can kind of look there and trace it back into, like, where is the roughly equivalent spot where you're going to see, you know, this is the exact line. [24:47.700 --> 24:51.480] And sometimes it actually has an APKTool like dot line 80. [24:52.040 --> 24:56.340] So, you can see kind of where in the original code you're looking at. [24:58.120 --> 25:03.280] And then you can add a debugging statement or modify the behavior in the back Smalley code. [25:04.200 --> 25:12.320] And then rebuild it with APKTool B, which builds it back into the APK that you want to be analyzing. [25:14.220 --> 25:23.780] And then if you want to look at it again, look at a similar place in the code, you know, change other behaviors, then you just repeat this process. [25:27.580 --> 25:34.160] So, yeah, that's, you know, using those two tools in combination can provide a pretty powerful methodology for your reversing. [25:34.660 --> 25:37.100] There's also some other useful tools. [25:39.380 --> 25:47.340] Well, to go back, this run, rinse, repeat process, you know, includes the word run. [25:47.620 --> 25:50.780] So, it's not purely a static analysis combo. [25:50.780 --> 25:55.360] So, I cheated a bit because it does involve some dynamic analysis. [25:55.920 --> 26:13.260] And so, when you're introducing a debugging statement, then you could use ADB logcat and then use the PID option to see where the system logs are spitting that bit of debugging information that you've introduced. [26:13.700 --> 26:30.460] It also gives you some interesting things like the loading of... the dynamic loading of DEX classes which, you know, is basically a file that is compiled so that the architecture that you're running on... [26:31.240 --> 26:37.300] it can basically be... an OAT is running directly on the CPU. [26:37.300 --> 26:43.400] It's not running on the Java level. [26:43.400 --> 26:46.420] It's just basically running directly on the CPU. [26:46.760 --> 26:56.460] And when you run a DEX 2 OAT, then that's something that is taking Java classes and making it interpretable by the CPU to run. [26:56.700 --> 26:59.220] And that's sometimes interesting to look at. [27:00.240 --> 27:06.100] So, you can also use S-Trace on the Android platform. [27:06.460 --> 27:21.440] And this is useful in cases where you have a piece of malware, for instance, that's calling, like, an unlink to delete a file or raw file IO or raw network IO that you want to see. [27:25.210 --> 27:31.250] And finally, there's something called Frida which is completely awesome. [27:32.530 --> 27:37.530] So a lot of dynamic analysis involves both control and observation. [27:38.450 --> 27:42.850] And the control part of this equation is done by Frida. [27:43.410 --> 27:52.050] It's an instrumentation toolbox which allows you to change running code as it's running and introduce scripts. [27:52.190 --> 28:07.210] If you've ever used Grease Monkey in the past, it was this awesome thing back in the day which allowed you to just kind of, you know, say, hey, here's a JavaScript, a bit of JavaScript that I want to drop into this web page to, oh, I don't know, say, like, [28:08.270 --> 28:11.970] circumvent the New York Times' paywall or something like that. [28:12.410 --> 28:19.150] And you can just kind of erase some elements and then, you know, have that JS run every time in the web page. [28:19.150 --> 28:21.150] This is kind of similar. [28:21.470 --> 28:29.530] You can use Frida to run scripts that modify the Java behavior within a running app. [28:29.650 --> 28:34.870] So it's a really powerful, awesome tool to insert code into running processes. [28:35.330 --> 28:39.570] For instance, you can make it auto accept forged certificates as well. [28:40.870 --> 28:45.970] Or block the unlink command that deletes files from the Android system. [28:49.810 --> 28:55.870] So in this equation, the observation part can be, for instance, man in the middle proxy. [28:56.630 --> 29:00.850] And MITM proxy generates a forged certificate. [29:01.530 --> 29:06.890] And then you're supposed to, you know, install that forged certificate on the host platform. [29:06.890 --> 29:11.430] And then it'll just accept that. [29:11.710 --> 29:17.210] And you have, you know, SSL encrypted traffic that is observable. [29:18.950 --> 29:25.310] So using a Frida script, you can basically have it accept all sorts that are introduced. [29:25.310 --> 29:40.010] And we did this with the Ring Doorbell app and found a bunch of third parties that were loaded Into the Ring Doorbell app. [29:47.580 --> 29:50.920] And here's an example of, for instance, what we found. [29:51.080 --> 29:54.700] We found a lot of information that was just being relayed to third parties. [29:54.840 --> 29:55.700] I'll go into that in a minute. [29:58.750 --> 30:09.710] So bringing it all together, you can use static analysis to look at the code paths, enumerate the code as best you can, try to figure out what's happening in the app. [30:09.870 --> 30:17.850] And then you can use dynamic analysis with Frida to change functionality, mock out certain functions, do things that it's not meant to do. [30:18.010 --> 30:21.170] And observe the behavior once you do that. [30:21.590 --> 30:25.590] Say introduce a lot more debugging code, look at what's there. [30:26.910 --> 30:33.910] And you can use static analysis again if you get to a stage two payload in an Android app. [30:33.910 --> 30:40.490] Something that's deeper and buried deeper in the code that you want to reverse itself. [30:44.570 --> 30:50.220] So a few months ago I was interested in looking at this Tor Hydra malware. [30:50.220 --> 30:56.520] It's a class of malware and it's modified its behavior somewhat. [30:56.760 --> 31:14.260] But the basic gist of it is that it kind of masquerades as banking software and uses accessibility features that are in Android to gain a lower level of control over the operating system. [31:15.540 --> 31:26.060] Accessibility permissions allow apps to install other apps, control and read the screen. [31:26.960 --> 31:28.940] You know, introduce keystrokes. [31:29.320 --> 31:32.280] It's very powerful permission that shouldn't be taken lightly. [31:33.320 --> 31:44.800] And it's mostly for folks that are disabled that need those permissions, need that kind of help with various aspects of their mobile experience. [31:46.460 --> 31:53.320] But this piece of malware, which can be found on Malware Bazaar, that's where a lot of it can be found. [31:53.320 --> 31:55.820] That's a really useful tool in downloading. [31:56.480 --> 32:01.800] You can also find a lot of these things on buyers total, for instance, different samples. [32:02.460 --> 32:05.020] So this is getting kind of the primary material study, right? [32:07.380 --> 32:09.500] And this is what it looks like, the interaction here. [32:10.640 --> 32:13.960] So you click on the app, which is the top left icon here. [32:15.220 --> 32:17.300] I apologize for the slowness. [32:18.840 --> 32:22.240] And so it opens this thing that says, hey, I'm your bank. [32:22.540 --> 32:24.000] By the way, I need this permission. [32:27.780 --> 32:30.720] And so it asks for this accessibility permission. [32:35.690 --> 32:47.810] And then when you go and grant it, there's a bunch of stuff that automatically happens very quickly. [32:49.150 --> 32:57.010] Because it now has access to a very low level of your operating system and can install things and do things that are shady. [33:01.200 --> 33:02.860] Not sure if we're at the loop point yet. [33:06.990 --> 33:10.370] So we wanted to study this malware and see what it was doing. [33:11.750 --> 33:15.410] First step was looking at the android manifest.xml file. [33:16.910 --> 33:19.210] That was pretty interesting. [33:19.370 --> 33:23.450] As I said, it had the ability to read and send SMS messages. [33:23.610 --> 33:24.690] That propagates... [33:24.690 --> 33:27.630] That's a way that is common for malware to propagate itself. [33:27.630 --> 33:31.270] Sending your SMS messages to your contacts. [33:31.610 --> 33:36.870] It can itself install and delete packages that you've installed. [33:36.870 --> 33:42.210] So if you want to get rid of it, if you have some antivirus software that can possibly get rid of this malware, it can uninstall that. [33:43.110 --> 33:48.310] Read contacts so it can propagate better with the SMS messages that it is allowed to send. [33:48.650 --> 33:49.930] And initiate calls. [33:50.150 --> 33:55.550] A lot of permissions that should raise some eyebrows if you're installing anything. [33:57.710 --> 34:00.130] And, you know, as I said, the accessibility service. [34:02.850 --> 34:06.410] Interestingly, look at all these permissions... [34:06.410 --> 34:14.570] Sorry, this is a list of the activities, the screens that this is allowed to run. [34:15.010 --> 34:24.350] But if you look at these com.ombth whatever, that is not present in the reversed code. [34:24.650 --> 34:27.630] That specific code path does not exist. [34:27.630 --> 34:36.410] So it's asking for permission to run something that it doesn't have in its reverse code. [34:36.670 --> 34:38.090] So it's doing something. [34:38.270 --> 34:43.550] It's actually trying to dynamically load Java classes in order to... [34:43.550 --> 34:47.630] You know, at runtime, in order to run something else. [34:47.790 --> 34:54.090] It's basically a deeper level of code than is presented when it is first installed. [34:54.090 --> 34:57.630] So what you find is that... [34:59.370 --> 35:03.490] You want to find where this is dynamically loaded from. [35:03.790 --> 35:09.710] So you can use Frida and previous iterations of the Tor Hydra malware. [35:09.830 --> 35:13.010] By the way, we'll get into why it's called Tor Hydra. [35:13.010 --> 35:15.010] It uses the Tor network. [35:15.290 --> 35:31.750] But the previous iterations of the Tor Hydra malware used an unlinked syscall in order to delete an APK that loaded a bunch of new classes into the runtime environment. [35:33.130 --> 35:35.870] I did not detect that happening. [35:36.190 --> 35:41.750] But what I did see is that if you look at the Frida code on the left... [35:43.610 --> 35:49.310] I was trying to figure out if it was just, you know, loading... [35:49.310 --> 35:52.250] You know, dynamically loading classes or not. [35:52.250 --> 36:05.990] And what I found is that using the script on the left and running it, Frida's output says that there's a bunch of different classes that are dynamically loaded when the app is first run. [36:09.530 --> 36:12.650] And so where are these Java classes coming from? [36:12.650 --> 36:22.830] Is it an instance, again, of using strace to unlink a file that is loading a bunch of, you know, new classes into the app? [36:23.410 --> 36:27.030] And then, you know, deleting all traces of it from the disk? [36:27.430 --> 36:28.930] Well, no, I didn't find that. [36:29.070 --> 36:31.590] I didn't find any unlinked syscalls, actually. [36:32.390 --> 36:40.730] But what I did was I used Frida to block file.delete calls in Java. [36:41.650 --> 36:47.890] And that's another way to remove a file from the disk. [36:48.850 --> 36:58.950] So this class of malware is evolving to use different things in order to kind of obscure the way that it's operating. [36:59.370 --> 37:13.030] And interestingly, when I enumerated the files that it deleted, I found that there was this base.apk.a bunch of garbled text that it deleted. [37:13.350 --> 37:15.830] And I was like, hmm, that's kind of an interesting name. [37:15.990 --> 37:20.790] It's another apk that's dynamically being loaded and then deleted. [37:23.970 --> 37:40.130] So what you do is you take that, you know, deeper file and then use ADB, which is the Android debugger, to pull that file onto the disk and then use G8x to decompile that file. [37:40.130 --> 37:51.130] And in that case, on the left here, I did see all of the classes that this piece of malware was asking permission to actually display. [37:54.590 --> 38:04.050] And you'll see a lot in this code, this bit of code on the right, and this is a string obfuscation code. [38:04.050 --> 38:13.450] So you can see in the previous screenshot that there's a lot of things that you can determine just from using jadex. [38:13.710 --> 38:22.130] For instance, the stop Tor update status or, you know, is Tor connected methods. [38:22.450 --> 38:25.730] But a lot of the strings are obfuscated. [38:25.730 --> 38:37.930] In this case, you know, there's these calls on a cursor, like right here, that's like str3 does not equal and then some random crap. [38:38.490 --> 38:40.390] And you're not really sure what that means. [38:40.570 --> 38:46.870] But you can just take that random crap and then put it into a Java sandbox. [38:46.870 --> 38:54.670] And this is accompanied by a string of bytes, which is the dollar sign variable. [38:55.170 --> 38:56.050] Oh, sorry. [38:56.210 --> 39:14.150] Yeah, the dollar sign variable defines a function in another part of the code in the same scope that takes some byte array and then kind of looks it up in a chart what this string is. [39:14.150 --> 39:31.130] And you can take that function and put that in a Java sandbox and then take this function call and put that in a Java sandbox and then get the string, the original string that it was intending to appear here. [39:31.970 --> 39:36.490] You know, and get that original string, you know, what it was actually saying. [39:38.210 --> 39:46.190] So, in this, there was this bit of code that was called loadadminurl here. [39:46.450 --> 39:48.550] That's an interesting kind of function name, right? [39:49.830 --> 39:50.670] What's this? [39:52.570 --> 39:54.950] That's torv3 onion address. [39:55.850 --> 40:00.210] And, yeah, so in this case, I got an onion. [40:02.390 --> 40:09.750] And if you load that onion, it gives you a clearnet url and then closes tor down. [40:11.490 --> 40:16.530] And so, if you go to that clearnet url, this is what you get. [40:16.810 --> 40:19.810] You get the command and control center login page. [40:20.970 --> 40:22.970] So, that's really neat. [40:23.750 --> 40:34.250] What I suspect is going on here is that it loads tor in order to do discovery of the clearnet url. [40:34.950 --> 40:43.390] And, since tor is censorship resistant, you can't shut down a tor url very easily, if at all. [40:43.650 --> 40:47.870] And so, you have the discovery of a clearnet url. [40:48.050 --> 41:06.170] So, that even when that clearnet url is taken down through the normal processes of urls being taken down on the Internet, that this onion url, which makes the command and control discoverable, is still operating. [41:06.630 --> 41:11.850] And you can just change what command and control url is pointing to. [41:12.370 --> 41:19.170] So, that's kind of the discovery mechanism of this piece of malware, the CNC. [41:20.690 --> 41:31.510] So, in the end, the results that we find from this piece is the discovery of a command and control center that was operating via the tor network. [41:32.690 --> 41:38.610] And the uncovering of the evolution of some of this malware, the Hydra malware. [41:40.110 --> 41:44.530] And, hopefully, better signatures for antivirus software. [41:47.510 --> 41:48.790] How am I doing on time? [41:52.480 --> 41:56.790] So, we did the same kind of thing with the Ring doorbell app. [41:58.170 --> 42:17.910] And what we found was that, basically, if you use this methodology to set up IP tables and run it all through... run all web traffic through port 8080, then you can use man-in-the-middle proxy to intercept traffic. [42:18.310 --> 42:43.510] And if you run Frida to accept all those JavaScript... or Java... accept the certificates that man-in-the-middle presents, which mocks out the Java Trust Factory function, then you can see that in the case we're looking at the Ring doorbell, there was a bunch of third parties that it was sending traffic to. [42:44.450 --> 42:50.610] And, interestingly, out of these four third parties, only Mixpanel was mentioned. [42:50.850 --> 42:55.230] So, we called them out for that, for the privacy violations in that case. [42:59.110 --> 43:23.310] So, all of this is done in a lab setting where you have this setup where you have a laptop, and that's controlling your Android device, and perhaps man-in-the-middle proxy is running on Raspberry Pi, and you connect the device, the mobile device, onto the Raspberry Pi, [43:23.470 --> 43:26.090] and it's automatically man-in-the-middled. [43:26.830 --> 43:27.830] And that's great. [43:28.050 --> 43:31.290] You know, you have a very kind of sophisticated, controlled setup. [43:31.490 --> 43:36.370] You can have a monitor device, a control laptop, and a man-in-the-middle access point. [43:37.150 --> 43:40.490] So, all three of these, you know, are in a very controlled environment. [43:40.490 --> 43:42.210] You can do experiments with. [43:42.630 --> 43:49.290] But there are distinct disadvantages in that this isn't actually how things work in the real life, right? [43:49.490 --> 44:12.910] Like, when you're using an app, maybe you're going to unlock a car that's nearby, or, you know, it's going to change its behavior based on, you know, based on a location, or whether it's near other devices, NFC proximity, Bluetooth proximity, any number of things. [44:13.670 --> 44:19.970] Or, perhaps, you just have credentials that you don't want to be, you know, permanently in a lab. [44:20.070 --> 44:26.650] You have a specific device that's out in the field that you want to do some man-in-the-middling with. [44:27.230 --> 44:29.310] Or I should say machine-in-the-middling with. [44:29.590 --> 44:39.070] So, you have, you know, this... you want a setup that kind of really combines all of these aspects into a single device. [44:40.270 --> 44:43.270] And I was thinking, okay, well, how do you do that? [44:43.370 --> 44:48.110] You need the control, you need Frida on your mobile device. [44:48.250 --> 44:59.650] Well, there is something that allows you to have, you know, a full Linux environment that, you know, Frida is requiring to run in order to control the device. [44:59.810 --> 45:06.210] You can actually just install Debian on an Android device using Linux Deploy. [45:07.910 --> 45:15.730] So, the goal is to combine all these pieces of infrastructure onto a single device that can kind of monitor itself while in the field. [45:17.090 --> 45:30.770] And a secondary goal is to perhaps do this in a way that allows someone who has specialized credentials to be separate from someone who's actually auditing the app. [45:31.430 --> 45:40.590] And so, you want some remote party to be able to audit the app and not be in the physical, say, workplace, et cetera. [45:44.100 --> 45:48.440] So, first of all, we'll have an Android device and it's rooted. [45:48.800 --> 45:56.460] And it has, you know, lineage OS with Magisk Manager on it, which is something that allows some deep level of access. [45:57.520 --> 46:01.280] And then, you know, I'll go through this real quickly here. [46:01.760 --> 46:27.040] The methodology is install Frida on a full Linux deploy, true to Debian environment on the device, install man-in-the-middle proxy on that device as well, and then install simple SSHD on the device on the host, and then use that to transfer the man-in-the-middle proxy credentials to the host operating system. [46:28.140 --> 46:41.160] And then, you install Frida server via this Magisk module and set up IP tables for interception of that app based on a specific UID. [46:41.440 --> 46:50.900] So, every app running in Android has its own UID, which will be separate and which you can look up. [46:50.900 --> 47:01.920] And IP tables conveniently provides a way for you to only intercept traffic coming from originally, originating from a specific UID. [47:02.280 --> 47:06.900] So, you can filter out all the traffic and only focus on the one that you want to actually look at. [47:08.900 --> 47:16.980] And then, you know, you run Frida with an intercept script, and then watch the traffic flow. [47:21.100 --> 47:24.340] So, the remote auditor has a similar process. [47:24.600 --> 47:32.980] They install SSHD on a Linux deploy. [47:34.340 --> 47:41.940] And then, you install, say, something like WireGuard, which allows you to be on the same local network very easily. [47:42.740 --> 47:47.860] And then, you are a remote auditor and you SSHD into the device. [47:48.180 --> 47:56.760] And then, you're able to run those, you know, Frida commands or whatever to change the behavior of whatever app you want, or monitor that behavior. [47:57.500 --> 48:07.180] So, the conclusion here is that apps deploy a number of techniques to kind of make it hard to inspect that underlying traffic and behaviors. [48:08.320 --> 48:09.760] But, it's not impossible. [48:10.160 --> 48:20.860] And with the use of some great tools at our disposal, like JDX, like APK tool, like Frida, we can inspect malware and audit the privacy of apps we rely on daily. [48:21.900 --> 48:27.640] In addition, apps may change their behavior because they're being monitored. [48:27.980 --> 48:29.000] They know they're being monitored. [48:29.140 --> 48:31.500] They're in, you know, some kind of lab. [48:32.100 --> 48:36.840] Bossware or stalkerware may only work on a specific device, credentialed device. [48:38.180 --> 48:44.640] In this case, you know, an app does not prevent us from monitoring the traffic of these devices. [48:46.340 --> 48:59.780] But, if we divorce our analysis of apps from the lab and move this all on a single device, we can actually see the real behavior of a piece of stalkerware, malware, or bossware. [48:59.780 --> 49:00.300] for instance. [49:03.680 --> 49:04.600] Thanks very much. [49:05.100 --> 49:08.380] So, yeah, if you have questions... [49:24.090 --> 49:25.130] Castan, can you hear me? [49:25.570 --> 49:25.730] Yes. [49:26.410 --> 49:28.190] First of all, thank you for the excellent talk. [49:29.130 --> 49:35.070] So, I'm not sure if I asked this correctly, but... So, I was wondering if you could just... [49:35.070 --> 49:35.590] Oh, sorry. [49:35.770 --> 49:43.350] If you could just briefly talk about the state of... I know this is an Android talk, but you could talk about the state of, like, iOS analysis also. [49:43.690 --> 49:53.490] And just from your experience... So, I'm an iOS user, and I'd like to analyze, like, a lot of the apps that I use, like, rewards programs and that kind of stuff. [49:53.670 --> 49:57.630] A lot of these companies, they make an equivalent app for Android. [49:58.430 --> 50:07.670] Would it make sense from your point of view to... Like, is it easier to analyze the Android version of the app and maybe get some clues as to how the iOS version might be working? [50:07.930 --> 50:15.070] You know, with the assumption that a lot of these companies are developing the same app with the same backend for both Android and iOS? [50:15.410 --> 50:18.390] Yeah, I think that's definitely a great suggestion. [50:18.690 --> 50:26.050] You know, seeing what the behavior of an Android app is and then using that, applying that knowledge to analyze iOS apps. [50:26.170 --> 50:28.930] I'm not an iOS app reverser. [50:29.230 --> 50:33.310] I just don't know much about that entire field. [50:33.930 --> 50:37.970] So, I can't really speak to the specifics of iOS reversing. [50:39.170 --> 50:58.730] But matter specs for that, because that's, you know, I think somewhat more difficult perceived because of the inaccessibility of apps and the way that you download them and the closed ecosystem that it operates in. [51:01.390 --> 51:04.010] You didn't mention app signing. [51:04.510 --> 51:05.670] Yeah, I didn't. [51:05.990 --> 51:07.510] Are APKs signed? [51:08.490 --> 51:21.130] So, in the case where you need to... in the case where you're backsmalling and then rebuilding an app, you have to uninstall the original app and then sign that you're a copy of an app. [51:21.130 --> 51:31.210] The way that app signing works in the Android ecosystem is that basically Android will let you install an app with any signature. [51:31.670 --> 51:35.590] But if you upgrade that app, then it needs to have the same set of signatures. [51:36.530 --> 51:41.890] And if you uninstall an app, you can reinstall it with a different set of signatures. [51:42.110 --> 51:45.010] So, yeah, that is kind of part of the process. [51:45.010 --> 51:52.210] I don't understand why the auditor needs to install SSHD rather than just SSH client. [51:54.130 --> 51:54.810] The... [51:54.810 --> 51:56.430] Remote auditor. [51:56.810 --> 51:56.990] Yeah. [51:57.230 --> 52:01.010] So, your host needs SSHD. [52:01.770 --> 52:17.930] So, if you're, you know, have a Android device, your host needs SSHD in order to transfer the man-in-the-middle proxy certificate to the host in order for it to be accepted via the script. [52:18.350 --> 52:18.450] Okay. [52:19.030 --> 52:27.390] And can apps detect the MITM proxy as circumvention? [52:27.390 --> 52:30.050] Yeah, good question. [52:30.990 --> 52:50.590] So, apps will... the apps themselves will, you know, may enforce a higher level of certificate checking than just a trust factory kind of, you know, bypass. [52:51.290 --> 53:01.530] And in that case, you'll need to kind of inspect that area of the code and see what it's doing and then knock out that function call. [53:01.850 --> 53:14.310] So, it might be a process of using Frida to kind of look at what method is being employed to accept the certificates and then bypassing that. [53:16.370 --> 53:17.210] Thanks so much. [53:17.310 --> 53:28.430] I think that gets to my question, which was going to be about more sophisticated apps that detect either that they're in a sandbox or that check a checksum or that it implements certificate pinning and if you have any tips for working in that environment. [53:30.850 --> 53:31.290] Yeah. [53:31.290 --> 53:41.210] Apps can be incredibly... malware can be incredibly innovative when it wants to be and when it's employing methods of obfuscation. [53:41.850 --> 53:46.290] And I think the best thing to have is patience at that point. [53:46.910 --> 54:03.510] If you're looking at an app and you're reversing it, you get to a point where you have a specific code block and you want to, you know, that that's the code block that is enforcing certificate, some higher level of certificate pinning or whatever. [54:05.510 --> 54:12.130] And just getting through that process is, it can be extremely frustrating, but yeah, it takes time. [54:14.390 --> 54:15.170] Yeah, thank you. [54:15.270 --> 54:15.970] That was really cool. [54:16.190 --> 54:25.170] It was kind of surreal because I maintain the app Orbot and a lot of the Hydra method signatures were ripped right from that app status and stuff. [54:25.350 --> 54:32.110] But I was wondering if you know of any tools or tips for, like, apps that are built with, like, cross-platform frameworks. [54:32.290 --> 54:34.910] Those have kind of been, like, stumbling blocks for me when I've been trying to reverse stuff. [54:35.030 --> 54:38.110] Like, React Native is one that, like, I've never built an app with that. [54:38.130 --> 54:42.610] So when I suspect that an app has been built with the tools like that, I just kind of, like, hit a wall mostly. [54:44.250 --> 54:44.610] Yeah. [54:44.610 --> 54:48.510] Actually, when we were seeing this code, there was a folder just called Tor Project. [54:48.810 --> 54:57.290] And there's also all underscore Tor dot zip, which just includes a bunch of Tor code in the malware just directly. [54:57.650 --> 54:59.210] And malware does some weird, funky stuff. [54:59.390 --> 55:00.130] Like, you don't need to do that. [55:04.010 --> 55:05.170] Sorry, can you repeat your question? [55:05.870 --> 55:10.690] Like, apps, like, basically cross-platform tools, like React Native or Xamarin. [55:11.170 --> 55:11.210] Right. [55:11.210 --> 55:13.310] But I guess I'm more interested in, like, React Native. [55:13.410 --> 55:15.210] Do you know if there are tools to... [55:15.210 --> 55:17.190] I don't know of them. [55:17.290 --> 55:17.750] There might be. [55:17.890 --> 55:18.590] I'm not really sure. [55:18.690 --> 55:19.290] I haven't looked at that. [55:19.470 --> 55:19.710] Yeah. [55:20.430 --> 55:20.830] Because...okay. [55:21.210 --> 55:21.410] Sorry. [55:21.570 --> 55:21.810] Thank you. [55:26.340 --> 55:27.560] So thanks very much. [55:27.660 --> 55:30.060] I don't think that we have time for any more questions. [55:30.060 --> 55:33.220] But certainly, I'll be around for the entire weekend. [55:33.560 --> 55:38.740] And feel free to maybe talk to me upstairs. [55:39.360 --> 55:40.800] And thanks very much for coming. [55:54.870 --> 55:56.070] Just a quick announcement. [55:56.430 --> 56:00.270] At 9 o'clock, we're going to be doing something kind of different, something we haven't done before. [56:00.290 --> 56:05.190] We actually are going to have a marching band walking around the conference site. [56:05.610 --> 56:08.750] So feel free to come by and take a look.