Working Principle
Reading location beacons with the code to restore access to the target account
The main security vulnerability is the mechanism of password recovery via SMS. This method allows to intercept a data packet through the SS7 transmission protocol vulnerability and obtain the login and authorization password. To crack the password, DeviceLocator uses a certain sequence of actions leading to the identification of the phone number tied to the account. The software then initiates a password recovery procedure via a passcode with an access code and intercepts the sent message. Using the received code, the application passes authorization to the account on the virtual device.
| likelihood | severity | incidents | |
|---|---|---|---|
|
SIM swap
|
|
|
3.4k takeovers |
|
Phishing
|
|
|
8.7k reports |
|
Signal loss
|
|
|
2.1k incidents |
|
Location history
|
|
|
1.2k exposures |
|
Weak recovery
|
|
|
4.0k attempts |
|
Credential stuffing
|
|
|
2.8k compromises |
|
Malicious clients
|
|
|
1.5k downloads |
|
Social engineering
|
|
|
6.0k reports |
|
Metadata leakage
|
|
|
12k records |
|
Device compromise
|
|
|
420 incidents |
Wij gebruiken browsercookies die nodig zijn voor het goed functioneren van de website. Bijvoorbeeld, wij slaan uw instellingen voor gegevensverzameling van de website op zodat we hieraan kunnen voldoen als u terugkeert naar onze website. U kunt deze cookies uitschakelen in uw browserinstellingen, maar als u dit doet, werkt de website mogelijk niet zoals bedoeld.
Om gebruikersgedrag te begrijpen om u een relevantere browse-ervaring te bieden of om inhoud op onze website te personaliseren. Bijvoorbeeld, we verzamelen informatie over welke pagina's u bezoekt om relevantere informatie te kunnen bieden.
Om advertenties op onze website en andere websites te personaliseren en de effectiviteit ervan te meten. Bijvoorbeeld, we kunnen u gepersonaliseerde advertenties tonen op basis van de pagina's die u bezoekt op onze website.