Working Principle
Reading location beacons with the code to restore access to the target account
The main security vulnerability is the mechanism of password recovery via SMS. This method allows to intercept a data packet through the SS7 transmission protocol vulnerability and obtain the login and authorization password. To crack the password, DeviceLocator uses a certain sequence of actions leading to the identification of the phone number tied to the account. The software then initiates a password recovery procedure via a passcode with an access code and intercepts the sent message. Using the received code, the application passes authorization to the account on the virtual device.
| likelihood | severity | incidents | |
|---|---|---|---|
|
SIM swap
|
|
|
3.4k takeovers |
|
Phishing
|
|
|
8.7k reports |
|
Signal loss
|
|
|
2.1k incidents |
|
Location history
|
|
|
1.2k exposures |
|
Weak recovery
|
|
|
4.0k attempts |
|
Credential stuffing
|
|
|
2.8k compromises |
|
Malicious clients
|
|
|
1.5k downloads |
|
Social engineering
|
|
|
6.0k reports |
|
Metadata leakage
|
|
|
12k records |
|
Device compromise
|
|
|
420 incidents |
Vi använder webbläsarcookies som är nödvändiga för att webbplatsen ska fungera korrekt. Till exempel lagrar vi dina inställningar för datainsamling på webbplatsen så att vi kan följa dem om du återvänder till vår webbplats. Du kan inaktivera dessa cookies i dina webbläsarinställningar, men om du gör det kanske webbplatsen inte fungerar som avsett.
För att förstå användarbeteende för att ge dig en mer relevant surfupplevelse eller anpassa innehållet på vår webbplats. Till exempel samlar vi in information om vilka sidor du besöker för att hjälpa oss att tillhandahålla mer relevant information.
För att anpassa och mäta effektiviteten av reklam på vår webbplats och andra webbplatser. Till exempel kan vi visa dig personanpassade annonser baserat på de sidor du besöker på vår webbplats.