10 months ago
North Korean Hackers Exploit Google Find Hub to Target Android Devices
Imagine your phone has a special tool that helps you find it if you lose it, like a homing beacon.
Some bad guys, working for a country called North Korea, found a way to trick people into giving them the secret code to use this tool.
They sent fake messages that, when opened, let them steal the code.
Once they had the code, they could see where your phone was and even erase everything on it, like making it brand new again!
They could also spy on you with your camera.
Google says their finding tool is okay, but people need to make sure their secret codes are extra safe with special steps, like a double lock, so the bad guys can't get them easily.
North Korean hackers are exploiting Google Find Hub to remotely track and wipe Android devices.
The attack involves tricking users into revealing Google account credentials through malicious files, often delivered via chat apps like KakaoTalk.
Hackers install scripts to monitor devices, steal credentials, and then use Google Find Hub to control victims' phones.
Beyond Find Hub, attackers were able to surveil victims via webcam and gain remote control of devices.
Google states the attack did not exploit a flaw in Android or Find Hub, emphasizing the need for users to enable two-step verification or passkeys.
- Who
- North Korean state-backed hackers
- What
- Compromising Android devices by stealing Google account credentials and abusing Google Find Hub for remote tracking and wiping.
- Where
- Globally affecting Android phones and tablets
- When
- Recent development (specific date not mentioned)
- Why
- To steal credentials, monitor victims, track locations, and remotely wipe devices.
Vulnerable Devices
Google's Stance
Method of Attack
Vulnerable Devices
North Korean hackers are using malicious files sent through apps like KakaoTalk to compromise Android devices. These files install scripts that monitor and control the device, stealing Google account credentials. Hackers then use these credentials to access Google's Find Hub and remotely track and wipe victims' phones.
Google's Stance
Google states that this attack did not exploit any security flaw in Android or Find Hub. The attack required PC malware to be present to steal Google account credentials and abuse legitimate Find Hub functions.
Exploitation of Find Hub
Vulnerable Devices
Hackers gained remote control by compromising Google accounts and then used the Find Hub service to perform location tracking and remote wiping of Android devices.
Google's Stance
Google asserts that the attack abused legitimate functions within Find Hub, rather than exploiting a flaw in the service itself.
User Protection
Vulnerable Devices
Users are at risk due to the potential for malicious scripts and the compromise of Google account credentials.
Google's Stance
Google strongly urges users to enable two-step verification or passkeys for comprehensive protection against credential theft.
Key facts
- Threat Actor
- North Korean state-backed hackers
- Vulnerable Service
- Google Find Hub
- Attack Vector
- Malicious files via KakaoTalk, PC malware to steal Google credentials
- Capabilities
- Remote tracking, remote wiping, stealing credentials, webcam surveillance, remote device control
- Google's Response
- No flaw in Android or Find Hub exploited; urges users to enable 2-step verification or passkeys.
Quotes
Officials from Genians
Security firm Genians officials
“While Find Hub is intended to safeguard Android devices, this is the first confirmed case in which a state-sponsored threat actor obtained remote control by compromising Google accounts, then used the service to perform location tracking and remote wipe.”
timesnownews.com
Company spokesperson responding to Android Authority
“This attack did not exploit any security flaw in Android or Find Hub. The report indicates this targeted attack required PC malware to be present in order to steal Google account credentials and abuse legitimate functions in Find Hub. We strongly urge all users to enable two-step verification or passkeys for comprehensive protection against credential theft.”
timesnownews.com




