Working Principle
Reading location beacons with the code to restore access to the target account
The main security vulnerability is the mechanism of password recovery via SMS. This method allows to intercept a data packet through the SS7 transmission protocol vulnerability and obtain the login and authorization password. To crack the password, DeviceLocator uses a certain sequence of actions leading to the identification of the phone number tied to the account. The software then initiates a password recovery procedure via a passcode with an access code and intercepts the sent message. Using the received code, the application passes authorization to the account on the virtual device.
| likelihood | severity | incidents | |
|---|---|---|---|
|
SIM swap
|
|
|
3.4k takeovers |
|
Phishing
|
|
|
8.7k reports |
|
Signal loss
|
|
|
2.1k incidents |
|
Location history
|
|
|
1.2k exposures |
|
Weak recovery
|
|
|
4.0k attempts |
|
Credential stuffing
|
|
|
2.8k compromises |
|
Malicious clients
|
|
|
1.5k downloads |
|
Social engineering
|
|
|
6.0k reports |
|
Metadata leakage
|
|
|
12k records |
|
Device compromise
|
|
|
420 incidents |
เราใช้คุกกี้เบราว์เซอร์ที่จำเป็นสำหรับการทำงานของเว็บไซต์อย่างถูกต้อง ตัวอย่างเช่น เราจัดเก็บการตั้งค่าการเก็บรวบรวมข้อมูลเว็บไซต์ของคุณเพื่อให้เราสามารถปฏิบัติตามได้หากคุณกลับมาที่เว็บไซต์ของเรา คุณสามารถปิดใช้งานคุกกี้เหล่านี้ในการตั้งค่าเบราว์เซอร์ของคุณ แต่ถ้าคุณทำเช่นนั้น เว็บไซต์อาจไม่ทำงานตามที่ตั้งใจไว้
เพื่อทำความเข้าใจพฤติกรรมผู้ใช้เพื่อมอบประสบการณ์การเรียกดูที่เกี่ยวข้องมากขึ้นหรือปรับแต่งเนื้อหาบนเว็บไซต์ของเรา ตัวอย่างเช่น เราเก็บรวบรวมข้อมูลเกี่ยวกับหน้าที่คุณเยี่ยมชมเพื่อช่วยให้เราให้ข้อมูลที่เกี่ยวข้องมากขึ้น
เพื่อปรับแต่งและวัดประสิทธิภาพของการโฆษณาบนเว็บไซต์ของเราและเว็บไซต์อื่นๆ ตัวอย่างเช่น เราอาจแสดงโฆษณาที่ปรับแต่งตามหน้าที่คุณเยี่ยมชมบนเว็บไซต์ของเรา