{"id":23670,"date":"2016-08-19T11:43:56","date_gmt":"2016-08-19T03:43:56","guid":{"rendered":"http:\/\/www.upgrademag.com\/web\/?p=23670"},"modified":"2016-08-19T11:48:22","modified_gmt":"2016-08-19T03:48:22","slug":"risks-not-behind-pokemon-go","status":"publish","type":"post","link":"http:\/\/www.upgrademag.com\/web\/2016\/08\/19\/risks-not-behind-pokemon-go\/","title":{"rendered":"Risks &#8211; or not &#8211; behind Pok\u00e9mon Go"},"content":{"rendered":"<p><strong><em>By\u00a0Axelle Apvrille Anti-Virus Malware Researcher, FORTINET<\/em><\/strong><\/p>\n<p>At FortiGuard, we wouldn&#8217;t let you down without an analysis of Pok\u00e9mon Go. Is it safe to install? Can you go and hunt for Pok\u00e9mon, or stay by a pokestop longing for pokeballs? While this article won&#8217;t assist you in game strategy, I&#8217;ll give you my first impressions analyzing the game.<\/p>\n<p>Versions<\/p>\n<p>There are two sorts of Pok\u00e9mon applications:<\/p>\n<ol>\n<li><b>The\u00a0<i>official<\/i>\u00a0versions, issued by Niantic.<\/b><\/li>\n<\/ol>\n<p><a href=\"http:\/\/www.upgrademag.com\/web\/wp-content\/uploads\/2016\/08\/Risks-or-not-Behind-Pok\u00e9mon-Go-2.jpg\"><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-large wp-image-23671\" src=\"http:\/\/www.upgrademag.com\/web\/wp-content\/uploads\/2016\/08\/Risks-or-not-Behind-Pok\u00e9mon-Go-2-1024x210.jpg\" alt=\"Risks - or not - Behind Pok\u00e9mon Go -2\" width=\"640\" height=\"131\" srcset=\"http:\/\/www.upgrademag.com\/web\/wp-content\/uploads\/2016\/08\/Risks-or-not-Behind-Pok\u00e9mon-Go-2-1024x210.jpg 1024w, http:\/\/www.upgrademag.com\/web\/wp-content\/uploads\/2016\/08\/Risks-or-not-Behind-Pok\u00e9mon-Go-2-300x61.jpg 300w, http:\/\/www.upgrademag.com\/web\/wp-content\/uploads\/2016\/08\/Risks-or-not-Behind-Pok\u00e9mon-Go-2-768x157.jpg 768w\" sizes=\"auto, (max-width: 640px) 100vw, 640px\" \/><\/a><\/p>\n<p>We will talk more about these later, but in brief, they are not malicious.<\/p>\n<ol>\n<li><b>The\u00a0<i>hacked<\/i>\u00a0versions.<\/b>\u00a0These are also known as &#8220;mods&#8221;, which are issued by other developers, for multiple reasons. It is in this category we are the most likely to encounter malware. For instance, a repackaged version infected with DroidJack RAT has been identified to be in the wild (see analysis below).<\/li>\n<\/ol>\n<p>15db22fd7d961f4d4bd96052024d353b3ff4bd135835d2644d94d74c925af3c4<\/p>\n<p>However, not all hacked versions are necessarily malicious: we inspected hacks to play on Android 4.0 (the minimum requirement is normally 4.4), or to modify GPS coordinates, neither of which showed any malicious intent.<\/p>\n<p>baf0dc2e19c6ec9ebfc2853785e92e175064c522a82410c2e56e204fad156838 4d482cf9beef8d4f03a6c609025fc6025069c0c83598032e46380d23a75f1979<\/p>\n<p>Besides manual inspection, we also sent those samples to our learning-based Android prediction engine,\u00a0<a href=\"https:\/\/fortiguard.com\/paper\/2015-07-07-sherlockdroid-a-research-assistant-to-spot-unknown-malware-in-android-marketplaces\"><i>SherlockDroid \/ Alligator<\/i><\/a><i>,\u00a0<\/i>which confirmed our analysis \ud83d\ude09<\/p>\n<p><b>Risk #1 Installing an infected version<\/b><\/p>\n<p>As mentioned earlier, a sample with sha256<\/p>\n<p>15db22fd7d961f4d4bd96052024d353b3ff4bd135835d2644d94d74c925af3c4<\/p>\n<p>is infected with Android\/SandrC.tr, dubbed DroidJack RAT.<\/p>\n<p>This is a known malware, for which we have had a signature since 2015. Therefore, Fortinet customers were protected from this malicious Pok\u00e9mon app from the beginning \ud83d\ude42<\/p>\n<p>This malware is quite widespread. Internal statistics at Fortinet indicate more than 8,800 detections in a year, and 160 last month alone, but those figures are largely underestimated for various reasons, including the fact that reporting is not enabled by default. So, basically, what you should remember is that this malware is still in the wild and active currently.<\/p>\n<p>More malware to come?<\/p>\n<p>Yes, very certainly. Malware authors are likely to continue to re-package the game with a variety of malware and distribute it. The fact the game wasn&#8217;t released in all countries at the same date, for example, (thus forcing impatient users to look for alternatives on the web), combined with the fact there are large game hacking (that&#8217;s nice) and cheating (that&#8217;s bad \ud83d\ude09 communities only increase the potential for downloading an infected version of the game..<\/p>\n<p><b>Risk #2 Full Google Account Information? (This is fixed)<\/b><\/p>\n<p>Adam Reeve\u00a0<a href=\"http:\/\/adamreeve.tumblr.com\/post\/147120922009\/pokemon-go-is-a-huge-security-risk\">noticed<\/a>\u00a0that the game requested full access to your Google account. Note:\u00a0<i>we are not talking about an Android permission here but a permission of an app connected to a Google account<\/i>.<\/p>\n<p>This was an error and\u00a0<a href=\"https:\/\/support.pokemongo.nianticlabs.com\/hc\/en-us\/articles\/222648408-Permissions-update\">Niantic fixed this<\/a>. So be sure to\u00a0<a href=\"https:\/\/security.google.com\/settings\/security\/permissions?pli=1\">remove the permission<\/a>\u00a0from your account and upgrade your Pok\u00e9mon Go application.<\/p>\n<p>Finally, note that it is not extremely clear in the documentation exactly how much &#8220;full access&#8221; really means, but no malware or exploit of this has been reported so far.<\/p>\n<p><b>Risk #3 Unwanted network traffic<\/b><\/p>\n<p>In a perfect world, we&#8217;d expect games to only send packets over the network that are absolutely necessary for the game to run, such as your location, the details of Pok\u00e9mon around you, etc.<\/p>\n<p>However, this is very far from reality, and for years now most Android applications are bundled with third party kits (analytics, crash reporting, cross platform engines, etc.) which use up the bandwidth which send and receive more or less useful side information containing, in the best cases, the exact model of your smartphone, or in the worst, personal information such as your phone number and other private data.<\/p>\n<p>Pok\u00e9mon Go is one of these bandwidth hungry applications. I downloaded it two weeks ago, and it is already close to being the most greedy application on my phone&#8230;<\/p>\n<p><a href=\"http:\/\/www.upgrademag.com\/web\/wp-content\/uploads\/2016\/08\/Risks-or-not-Behind-Pok\u00e9mon-Go-1.jpg\"><img loading=\"lazy\" decoding=\"async\" class=\"alignleft wp-image-23672 size-medium\" src=\"http:\/\/www.upgrademag.com\/web\/wp-content\/uploads\/2016\/08\/Risks-or-not-Behind-Pok\u00e9mon-Go-1-180x300.jpg\" alt=\"Risks - or not - Behind Pok\u00e9mon Go -1\" width=\"180\" height=\"300\" srcset=\"http:\/\/www.upgrademag.com\/web\/wp-content\/uploads\/2016\/08\/Risks-or-not-Behind-Pok\u00e9mon-Go-1-180x300.jpg 180w, http:\/\/www.upgrademag.com\/web\/wp-content\/uploads\/2016\/08\/Risks-or-not-Behind-Pok\u00e9mon-Go-1-768x1278.jpg 768w, http:\/\/www.upgrademag.com\/web\/wp-content\/uploads\/2016\/08\/Risks-or-not-Behind-Pok\u00e9mon-Go-1-615x1024.jpg 615w, http:\/\/www.upgrademag.com\/web\/wp-content\/uploads\/2016\/08\/Risks-or-not-Behind-Pok\u00e9mon-Go-1.jpg 1440w\" sizes=\"auto, (max-width: 180px) 100vw, 180px\" \/><\/a><\/p>\n<p>For mobile users, the consumption of bandwidth is\u00a0<a href=\"https:\/\/haystack.mobi\/wordpress\/index.php\/2016\/06\/29\/the-bandwidth-costs-of-tracking-services-on-mobile-apps\/\">a real issue<\/a>. On average, 24% of an application&#8217;s traffic is for third party tracking and advertising services. For some applications, the rate rockets to 98%.<\/p>\n<p>While the percentage of side traffic for Pok\u00e9mon Go hasn&#8217;t been measured precisely, given the number of third party functionality it includes, I wouldn&#8217;t be surprised if it isn\u2019t well above 50% \ud83d\ude09<\/p>\n<p>Here is a list of what version 0.31.0 contains:<\/p>\n<ul>\n<li>Crittercism &#8211; now called Apteligent &#8211; is a mobile application &#8220;performance management solution&#8221;<\/li>\n<li>Dagger is a &#8220;fast dependency injector&#8221;<\/li>\n<li>Android support libraries: those are common to nearly all Android applications<\/li>\n<li>Apache commons I\/O<\/li>\n<li>Unity 3D: that&#8217;s the game engine Pok\u00e9mon Go heavily relies on<\/li>\n<li>Space Madness Lunar Console: this is a &#8220;lightweight Unity native iOS\/Android logger&#8221;<\/li>\n<li>Google Ads<\/li>\n<li>Google GSON<\/li>\n<li>Jackson XML: this is the JSON library for Java<\/li>\n<li>JNI bridge<\/li>\n<li>Upsight: a mobile analytics and marketing platform<\/li>\n<li>Google billing<\/li>\n<li>Square Otto: an event bus<\/li>\n<li>Voxel Busters: with &#8220;cross platform native plugins&#8221;<\/li>\n<li>rx for Reactive programming<\/li>\n<\/ul>\n<p>Along with such &#8220;not-so-essential&#8221; network traffic to third party servers also comes common leaks. While we expect Niantic Labs and Unity 3D (game engine) to access our geographic location (to locate Pok\u00e9mon and pokestops), perhaps we shouldn\u2019t expect apps like Crittercism, Google Ads, Jackson XML, or Upsight to retrieve our location?<\/p>\n<p>The disassembled code also shows that Voxel Busters is building the full list of our phone&#8217;s contacts (see figure below). They access the display name, phone number, phone and email of all contacts. The list is then compiled into a JSON object and sent to a function named UnitySendMessage, which is then exported by a Unity shared library (libunity.so) where it is dispatched to another function, and where I currently lose its track. Are contacts sent to remote servers? This is not confirmed yet, but is of some concern.<\/p>\n<p><a href=\"http:\/\/www.upgrademag.com\/web\/wp-content\/uploads\/2016\/08\/Risks-or-not-Behind-Pok\u00e9mon-Go-3.jpg\"><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-large wp-image-23673\" src=\"http:\/\/www.upgrademag.com\/web\/wp-content\/uploads\/2016\/08\/Risks-or-not-Behind-Pok\u00e9mon-Go-3-1024x613.jpg\" alt=\"Risks - or not - Behind Pok\u00e9mon Go -3\" width=\"640\" height=\"383\" srcset=\"http:\/\/www.upgrademag.com\/web\/wp-content\/uploads\/2016\/08\/Risks-or-not-Behind-Pok\u00e9mon-Go-3-1024x613.jpg 1024w, http:\/\/www.upgrademag.com\/web\/wp-content\/uploads\/2016\/08\/Risks-or-not-Behind-Pok\u00e9mon-Go-3-300x180.jpg 300w, http:\/\/www.upgrademag.com\/web\/wp-content\/uploads\/2016\/08\/Risks-or-not-Behind-Pok\u00e9mon-Go-3-768x460.jpg 768w\" sizes=\"auto, (max-width: 640px) 100vw, 640px\" \/><\/a><\/p>\n<p>So, yes, you need to know that while you play Pok\u00e9mon Go you send your geographic location, along with other details (e.g network operator name, phone brand, etc.), to several remote servers, and you &#8220;pay&#8221; for this side traffic through bandwidth consumption. Unfortunately, this is increasingly true for nearly any game found in application stores nowadays&#8230;<\/p>\n<p><b>Risk #4 Spoofed Pok\u00e9mon map or activity<\/b><\/p>\n<p>The Pok\u00e9mon Go application communicates with Niantic servers via HTTPS (see image below). Even better, in version 0.31.0, Niantic introduced\u00a0<a href=\"https:\/\/en.wikipedia.org\/wiki\/Transport_Layer_Security#Certificate_pinning\">certificate pinning<\/a>\u00a0to ensure that applications exchanged information with the real Pok\u00e9mon servers and not with others.<\/p>\n<p><a href=\"http:\/\/www.upgrademag.com\/web\/wp-content\/uploads\/2016\/08\/Risks-or-not-Behind-Pok\u00e9mon-Go-5.jpg\"><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter wp-image-23674 size-large\" src=\"http:\/\/www.upgrademag.com\/web\/wp-content\/uploads\/2016\/08\/Risks-or-not-Behind-Pok\u00e9mon-Go-5-1024x521.jpg\" alt=\"Risks - or not - Behind Pok\u00e9mon Go -5\" width=\"640\" height=\"326\" srcset=\"http:\/\/www.upgrademag.com\/web\/wp-content\/uploads\/2016\/08\/Risks-or-not-Behind-Pok\u00e9mon-Go-5-1024x521.jpg 1024w, http:\/\/www.upgrademag.com\/web\/wp-content\/uploads\/2016\/08\/Risks-or-not-Behind-Pok\u00e9mon-Go-5-300x153.jpg 300w, http:\/\/www.upgrademag.com\/web\/wp-content\/uploads\/2016\/08\/Risks-or-not-Behind-Pok\u00e9mon-Go-5-768x391.jpg 768w\" sizes=\"auto, (max-width: 640px) 100vw, 640px\" \/><\/a><\/p>\n<p><i>Initiating a TLS handshake with Pok\u00e9mon Go servers<\/i><\/p>\n<p>However, when certificate pinning is not active, an attacker can perform a MITM attack and thus completely modify the game for victims. For example,\u00a0<a href=\"https:\/\/github.com\/rastapasta\/pokemon-go-mitm-node\">rastapasta<\/a>\u00a0managed to customize pokestops!<\/p>\n<p><a href=\"http:\/\/www.upgrademag.com\/web\/wp-content\/uploads\/2016\/08\/Risks-or-not-Behind-Pok\u00e9mon-Go-6.jpg\"><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-large wp-image-23675\" src=\"http:\/\/www.upgrademag.com\/web\/wp-content\/uploads\/2016\/08\/Risks-or-not-Behind-Pok\u00e9mon-Go-6-576x1024.jpg\" alt=\"Risks - or not - Behind Pok\u00e9mon Go -6\" width=\"576\" height=\"1024\" srcset=\"http:\/\/www.upgrademag.com\/web\/wp-content\/uploads\/2016\/08\/Risks-or-not-Behind-Pok\u00e9mon-Go-6-576x1024.jpg 576w, http:\/\/www.upgrademag.com\/web\/wp-content\/uploads\/2016\/08\/Risks-or-not-Behind-Pok\u00e9mon-Go-6-169x300.jpg 169w, http:\/\/www.upgrademag.com\/web\/wp-content\/uploads\/2016\/08\/Risks-or-not-Behind-Pok\u00e9mon-Go-6-768x1365.jpg 768w, http:\/\/www.upgrademag.com\/web\/wp-content\/uploads\/2016\/08\/Risks-or-not-Behind-Pok\u00e9mon-Go-6.jpg 2025w\" sizes=\"auto, (max-width: 576px) 100vw, 576px\" \/><\/a><\/p>\n<p><i>\u00a0Hacked pokestop by\u00a0<\/i><a href=\"https:\/\/github.com\/rastapasta\/pokemon-go-mitm-node\"><i>rastapasta<\/i><\/a><\/p>\n<p>A malicious person can easily imagine other customizations, such as displaying an infected link in a pokestop, or directly injecting infected traffic. While such attacks are probably feasible, they are tricky, and the attack would only operate on the network where the Pok\u00e9mon Go MITM proxy is setup.<\/p>\n<p>Conclusion<\/p>\n<ul>\n<li>The Pok\u00e9mon Go application is\u00a0<b>not malicious<\/b>.<\/li>\n<li>It is no longer possible foe the application to fully access your email. It was a\u00a0<i>risk<\/i>\u00a0with an older version, but hasn&#8217;t ever been demonstrated.<\/li>\n<li>There are currently versions of Pok\u00e9mon Go in the wild repackaged with malware, and I expect more to come. Consequently, if you are not retrieving your applications from a safe application store I recommend you check its SHA256 hash against the official one, or scan the application with an anti-virus tool.<\/li>\n<li>Like most applications nowadays, Pok\u00e9mon Go (or the third party apps it uses) exposes your privacy and implies unwanted network traffic.<\/li>\n<li>Niantic has obviously paid attention to securing access to its gaming servers. However, locally, MITM proxy attacks remain possible by skilled attackers.<\/li>\n<\/ul>\n<p>Keep posted!<\/p>\n","protected":false},"excerpt":{"rendered":"<p>By\u00a0Axelle Apvrille Anti-Virus Malware Researcher, FORTINET At FortiGuard, we wouldn&#8217;t let you down without an analysis of Pok\u00e9mon Go. Is it safe to install? Can you go and hunt for Pok\u00e9mon, or stay by a pokestop longing for pokeballs? While this article won&#8217;t assist you in game strategy, I&#8217;ll give you my first impressions analyzing [&hellip;]<\/p>\n","protected":false},"author":7,"featured_media":23675,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[9,23,19,26],"tags":[495,169,34,286,4670],"class_list":["post-23670","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-apps","category-gaming","category-headlines","category-opinions","tag-cybersecurity-and-cybercrime","tag-fortinet","tag-gaming-2","tag-it-security","tag-pokemon-go"],"_links":{"self":[{"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/posts\/23670","targetHints":{"allow":["GET"]}}],"collection":[{"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/users\/7"}],"replies":[{"embeddable":true,"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/comments?post=23670"}],"version-history":[{"count":0,"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/posts\/23670\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/media\/23675"}],"wp:attachment":[{"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/media?parent=23670"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/categories?post=23670"},{"taxonomy":"post_tag","embeddable":true,"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/tags?post=23670"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}