Yahoo Android App Lets Attackers Send Spam

Yahoo has confirmed a vulnerability in its Mail app for Android is affecting a portion of its customers.

Some had suspected such a flaw was the actual cause of a spam campaign, which a number of researchers had initially claimed was caused by an Android botnet.

Microsoft engineer Terry Zink thought he had identified the first real evidence of an Android spamming botnet, having come across spam messages claiming to come from Yahoo accounts accessed on Google’s Android operating system. Sophos also believed it was likely an Android botnet was responsible for the spam.

Google subsequently denied Zink’s suggestion, claiming its research suggested spammers were “using infected computers and a fake mobile signature to try to bypass anti-spam mechanisms in the email platform they’re using.”

Other theories emerged, including one from security firm Lookout, which said it knew of vulnerabilities in the Yahoo Mail app for Android. Trend Micro also said it had uncovered a Yahoo! Android app vulnerability, which when exploited, allowed an attacker to send spammed messages using the compromised Yahoo account.

“We recently uncovered a vulnerability in Yahoo Android mail client, which can allow an attacker to gain access to a user’s Yahoo Mail cookie,” the firm wrote in a blog post. “This bug stems from the communication between Yahoo mail server and Yahoo Android mail client. By gaining this cookie, the attacker can use the compromised Yahoo Mail account to send specially-crafted messages. The said bug also enables an attacker to gain access to user’s inbox and messages.”

Yahoo opens up

In response to Trend’s findings, Yahoo said it had “learned of an isolated security vulnerability in the Yahoo Mail Android app. “Our analysis indicates that this vulnerability only arises when several external conditions coincide and, as such, is currently only affecting a small number of our Android users,” a spokesperson told TechWeekEurope. “We are actively working on resolving this issue and thank the security community for bringing it to our attention.”

Yahoo’s admittance might now finally put the rumours of a botnet of infected Android devices to rest. But Android is still being pummelled by cyber criminals.

Earlier this month, it emerged that over 100,000 had downloaded rogue Android apps from the official Google Play store, disguising themselves as popular Mario and Grand Theft Auto titles. Another 100,000 had downloaded Android malware from a third-party store in China, which was surreptitiously buying up apps on China Mobile’s Mobile Market.

Are you a security guru? Try our quiz!

Thomas Brewster

Tom Brewster is TechWeek Europe's Security Correspondent. He has also been named BT Information Security Journalist of the Year in 2012 and 2013.

Recent Posts

Programmer Sentenced To Five Years In Prison For Bitcoin Laundering

Ilya Lichtenstein sentenced to five years in prison for hacking into a virtual currency exchange…

47 mins ago

Hate Speech Watchdog CCDH To Quit Musk’s X

Target for Elon Musk's lawsuit, hate speech watchdog CCDH, announces its decision to quit X…

18 hours ago

Meta Fined €798m Over Alleged Facebook Marketplace Violations

Antitrust penalty. European Commission fines Meta a hefty €798m ($843m) for tying Facebook Marketplace to…

19 hours ago

Elon Musk Rebuked By Italian President Over Migration Tweets

Elon Musk continues to provoke the ire of various leaders around the world with his…

20 hours ago

VW, Rivian Launch Joint Venture, As Investment Rises To $5.8 Billion

Volkswagen and Rivian officially launch their joint venture, as German car giant ups investment to…

21 hours ago

AMD Axes 4 Percent Of Staff, Amid AI Chip Focus

Merry Christmas staff. AMD hands marching orders to 1,000 employees in the led up to…

1 day ago