Flaw That Allows a Malware to Steal 2FA Codes from Google Authenticator Could Have Been Fixed Long Back

The issue with Google Authenticator allowing screenshots was flagged way back in 2014.

Advertisement
By Darab Mansoor Ali | Updated: 9 March 2020 14:19 IST
Highlights
  • Cerberus malware take screenshot of Google Authenticator using RAT
  • Screenshots can be blocked using a simple FLAG_SECURE command
  • The issue was first flagged to Google in 2014
Flaw That Allows a Malware to Steal 2FA Codes from Google Authenticator Could Have Been Fixed Long Back

Google Authenticator was launched in 2010, as a safer alternative to sending OTPs over SMS

Last month, a Dutch cyber-security firm ThreatFabric discovered the first-ever malware that could hack Google Authenticator application to extract one-time passcodes from a user's device by taking a screenshot of a user's screen with Google Authenticator open. The malware, named Cerberus, was under development when it was found and the ThreatFabric report did not find any real-world attacks using the malware. Now, a new research has looked into the malware's ability to access the content on a user's screen. It says that this can be easily prevented by using a simple FLAG_SECURE command that prevents any attacker from gaining access to the user's screen content.

The new research from Night Watch Cybersecurity says that many Android applications with higher security requirements also use the FLAG_SECURE protocol. Night Watch Cybersecurity also filed a bug report with Google, which then filed an internal bug. They say that Google has not informed if the bug has been fixed, and that their internal tests reveal that the bug is still present, hence attackers can still take the screenshot of Authenticator on a victim's phone.

The report says that a Github user had flagged the issue way back in 2014. Nightwatch also says that they themselves flagged the issue to Google's security team earlier in 2017 as well. However, all they got was a bounty response the next day. The report also said that the Microsoft Authenticator also comes with the same flaw. Despite them blogging about it in 2018, the issue still remains in the Microsoft application.

The Cerberus malware is a new Android banking trojan that surfaced in 2019. It is a hybrid between a banking trojan and a remote access trojan that allows the attacker to generate OTPs on a victim's Google Authenticator app and take screenshots of the code using the Remote Access Trojan (RAT). It uses a simple technique of taking screenshots of the Authenticator app's interface, the ThreatFabric report had said last month.

For the latest tech news and reviews, follow Gadgets 360 on X, Facebook, WhatsApp, Threads and Google News. For the latest videos on gadgets and tech, subscribe to our YouTube channel. If you want to know everything about top influencers, follow our in-house Who'sThat360 on Instagram and YouTube.

Advertisement

Related Stories

Popular Mobile Brands
  1. OnePlus 13s Price in India Leaked Ahead of Launch on June 5
  2. Vivo S30, Vivo S30 Pro Mini Launched With 50-Megapixel Selfie Camera
  3. Realme Neo 7 Turbo With 7,200mAh Battery Goes Official; All Specifications
  4. Lava Bold N1, Lava Bold N1 Pro Debut in India With Budget Price Tags
  5. Tecno Pova Curve 5G Launched in India With This Price Tag
  1. MIT Study Reveals Why Roman Concrete Lasts Thousands of Years
  2. New Study Confirms Venus Is Still Geologically Active
  3. New Analysis Weakens Claims of Life on Distant Exoplanet K2-18b
  4. Viking Trade Routes More Expansive Than Thought, Finds Swedish Archaeologist After 5000 km Expedition
  5. China Launches AI-Powered Satellite Constellation to Build Space Supercomputer
  6. China and Russia Sign Deal to Build Lunar Nuclear Power Plant by 2036
  7. Starship Flight 8 Explosion Traced to ‘Flash’ in Rocket Engines, SpaceX Investigation Confirms
  8. 800-Year-Old Mummy Reveals Unusual Facial Tattoos Made from Rare Minerals
  9. SpaceX Cleared for Starship Flight 9 Launch After FAA Safety Review
  10. Vivo S30, Vivo S30 Pro Mini Launched With 6,500mAh Battery, 50-Megapixel Selfie Camera: Price, Specifications
Gadgets 360 is available in
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2025. All rights reserved.