Skip to main content

App-in-the-Middle attack bypasses Android for Work secure framework

Google’s enterprise mobility tool, formerly known as “Android for Work”, has 2 features that could allow an attacker to access data that should be protected by its sandboxed work environment.
Report a cyber attack: call 0300 303 5222 or email [email protected]

This content has been archived

This article no longer conforms to NHS Digital's standards for cyber alerts, and may contain outdated or inaccurate information. Use of this information contained in this page is at your own risk

Summary

Google’s enterprise mobility tool, formerly known as “Android for Work”, has 2 features that could allow an attacker to access data that should be protected by its sandboxed work environment.

Affected platforms

The following platforms are known to be affected:

Threat details

The Notification Access and Accessibility Permissions Service features have been found to be vulnerable. It was shown how a malicious app is installed in the personal profile and acts as an agent to steal information from and can control the Work profile and send it back to an attacker’s Command and Control server.

The risk posed here is significant in the sense that it should not be possible for any app in the personal profile, including a malicious one, to reach content from the work side. However, researchers found that a malicious app could bypass the divide using an “app-in-the-middle” attack and transmit stolen data to a remote attacker’s server.

The tool is popular with small, medium and large businesses as it creates a seemingly secure framework whereby sensitive enterprise information and private personal information are kept separate, allowing the coexistence of work productivity and user privacy.

The Notification Access Attack:
This app-in-the-middle attack was found in the Notification Access feature; Android for Work notices are presented alongside personal notifications in the same device interface. However, since Notification Access is a device-level permission, a malicious app in the personal profile can acquire permission to view and take actions on all notifications, including work notifications. Sensitive information such as calendar meetings, email messages and other information appear in these notifications, which are also visible to the “personal” malicious app.

If the attack is successful, it can manipulate a user to enable the Notification Access permission in order to gain access to information in the work profile. If the malicious app is designed to transmit the information viewed in notifications to a command and control server, then the information contained in notifications is no longer secure.
Furthermore, hackers can utilise this method to gain even greater access into sensitive work information by initiating a “forgot password” process on some enterprise system and hijacking the subsequent on-device notification to grant themselves full enterprise access, even outside of the context of the mobile device. Hackers can discreetly carry out the attack as it was found that the malicious app can immediately dismiss the notification and “archive” the recovery email using the Android Notifications API so the victim is completely unaware they have been hacked. This presents a serious threat to the use of Android for Work as a secure sandbox for mobile work productivity. The attacker may even capture 2-factor authentication and administrators will not have any visibility of the theft.


Remediation advice

Recommendations:

Remediation steps

Type Step

Highlighting this vulnerability brings to light the security implications of using BYOD within enterprises. Although it is appealing in terms of reducing costs, businesses need to consider the full implications of allowing corporate data to be accessed on personal devices that they could have little or no control over. Organisations need to consider what data can employees have access to and the security measures that are in place if an employee's device is lost, stolen or compromised.

IT hardware spend can be significantly reduced with a BYOD approach, although it may cost more for a company to integrate and support a diverse range of employee devices. The loss of devices with limited password protection is a concern – do enterprises have access to wipe data in the case of lost and stolen devices? With the convenience to the business to deploy a BYOD in the workplace, it does bring with it an increased risk from threats such as criminal hackers and malware intrusion. Data protection should be at the forefront of the business strategy because if it is compromised, the chances of criminals finding additional security loopholes would certainly increase. The key issue is to guard against data loss and leakage.

Security assessments are crucial to addressing this issue and a key takeaway is that education around employee device usage is necessary to ensure the safeguarding of data. One of the biggest risks is not having any sort of BYOD policy in place and it is imperative that businesses recognise the importance of taking action to ensure security policies are understood and followed by employees. If this is not heeded, it could lead to vulnerable exposure to criminal hackers and attacks leading to legislative and reputational damage.


Last edited: 17 February 2020 11:26 am