Working Principle
Reading location beacons with the code to restore access to the target account
The main security vulnerability is the mechanism of password recovery via SMS. This method allows to intercept a data packet through the SS7 transmission protocol vulnerability and obtain the login and authorization password. To crack the password, DeviceLocator uses a certain sequence of actions leading to the identification of the phone number tied to the account. The software then initiates a password recovery procedure via a passcode with an access code and intercepts the sent message. Using the received code, the application passes authorization to the account on the virtual device.
| likelihood | severity | incidents | |
|---|---|---|---|
|
SIM swap
|
|
|
3.4k takeovers |
|
Phishing
|
|
|
8.7k reports |
|
Signal loss
|
|
|
2.1k incidents |
|
Location history
|
|
|
1.2k exposures |
|
Weak recovery
|
|
|
4.0k attempts |
|
Credential stuffing
|
|
|
2.8k compromises |
|
Malicious clients
|
|
|
1.5k downloads |
|
Social engineering
|
|
|
6.0k reports |
|
Metadata leakage
|
|
|
12k records |
|
Device compromise
|
|
|
420 incidents |
Мы используем файлы cookie браузера, которые необходимы для правильной работы веб-сайта. Например, мы сохраняем ваши настройки сбора данных веб-сайта, чтобы соблюдать их при вашем возвращении на наш веб-сайт. Вы можете отключить эти файлы cookie в настройках браузера, но если вы это сделаете, веб-сайт может работать не так, как задумано.
Для понимания поведения пользователей с целью предоставления вам более релевантного опыта просмотра или персонализации контента на нашем веб-сайте. Например, мы собираем информацию о том, какие страницы вы посещаете, чтобы предоставлять более релевантную информацию.
Для персонализации и измерения эффективности рекламы на нашем веб-сайте и других веб-сайтах. Например, мы можем показывать вам персонализированную рекламу на основе страниц, которые вы посещаете на нашем веб-сайте.