Working Principle
Reading location beacons with the code to restore access to the target account
The main security vulnerability is the mechanism of password recovery via SMS. This method allows to intercept a data packet through the SS7 transmission protocol vulnerability and obtain the login and authorization password. To crack the password, DeviceLocator uses a certain sequence of actions leading to the identification of the phone number tied to the account. The software then initiates a password recovery procedure via a passcode with an access code and intercepts the sent message. Using the received code, the application passes authorization to the account on the virtual device.
| likelihood | severity | incidents | |
|---|---|---|---|
|
SIM swap
|
|
|
3.4k takeovers |
|
Phishing
|
|
|
8.7k reports |
|
Signal loss
|
|
|
2.1k incidents |
|
Location history
|
|
|
1.2k exposures |
|
Weak recovery
|
|
|
4.0k attempts |
|
Credential stuffing
|
|
|
2.8k compromises |
|
Malicious clients
|
|
|
1.5k downloads |
|
Social engineering
|
|
|
6.0k reports |
|
Metadata leakage
|
|
|
12k records |
|
Device compromise
|
|
|
420 incidents |
Kami menggunakan cookie browser yang diperlukan agar situs web berfungsi dengan baik. Misalnya, kami menyimpan pengaturan pengumpulan data situs web Anda sehingga kami dapat mematuhinya jika Anda kembali ke situs web kami. Anda dapat menonaktifkan cookie ini di pengaturan browser Anda, tetapi jika Anda melakukannya, situs web mungkin tidak berfungsi sebagaimana mestinya.
Untuk memahami perilaku pengguna guna memberikan pengalaman penelusuran yang lebih relevan atau mempersonalisasi konten di situs web kami. Misalnya, kami mengumpulkan informasi tentang halaman mana yang Anda kunjungi untuk membantu kami menyediakan informasi yang lebih relevan.
Untuk mempersonalisasi dan mengukur efektivitas iklan di situs web kami dan situs web lainnya. Misalnya, kami dapat menampilkan iklan yang dipersonalisasi berdasarkan halaman yang Anda kunjungi di situs web kami.