App-in-the-Middle attack bypasses Android for Work secure framework
This content has been archived
This article no longer conforms to NHS Digital's standards for cyber alerts, and may contain outdated or inaccurate information. Use of this information contained in this page is at your own risk
Summary
Affected platforms
The following platforms are known to be affected:
Threat details
The Notification Access and Accessibility Permissions Service features have been found to be vulnerable. It was shown how a malicious app is installed in the personal profile and acts as an agent to steal information from and can control the Work profile and send it back to an attacker’s Command and Control server.
The risk posed here is significant in the sense that it should not be possible for any app in the personal profile, including a malicious one, to reach content from the work side. However, researchers found that a malicious app could bypass the divide using an “app-in-the-middle” attack and transmit stolen data to a remote attacker’s server.
The tool is popular with small, medium and large businesses as it creates a seemingly secure framework whereby sensitive enterprise information and private personal information are kept separate, allowing the coexistence of work productivity and user privacy.
The Notification Access Attack:
This app-in-the-middle attack was found in the Notification Access feature; Android for Work notices are presented alongside personal notifications in the same device interface. However, since Notification Access is a device-level permission, a malicious app in the personal profile can acquire permission to view and take actions on all notifications, including work notifications. Sensitive information such as calendar meetings, email messages and other information appear in these notifications, which are also visible to the “personal” malicious app.
If the attack is successful, it can manipulate a user to enable the Notification Access permission in order to gain access to information in the work profile. If the malicious app is designed to transmit the information viewed in notifications to a command and control server, then the information contained in notifications is no longer secure.
Furthermore, hackers can utilise this method to gain even greater access into sensitive work information by initiating a “forgot password” process on some enterprise system and hijacking the subsequent on-device notification to grant themselves full enterprise access, even outside of the context of the mobile device. Hackers can discreetly carry out the attack as it was found that the malicious app can immediately dismiss the notification and “archive” the recovery email using the Android Notifications API so the victim is completely unaware they have been hacked. This presents a serious threat to the use of Android for Work as a secure sandbox for mobile work productivity. The attacker may even capture 2-factor authentication and administrators will not have any visibility of the theft.
Remediation advice
Recommendations:Remediation steps
Last edited: 17 February 2020 11:26 am