• nutbutter@discuss.tchncs.de
    link
    fedilink
    English
    arrow-up
    40
    ·
    edit-2
    13 hours ago

    Tldr? How?


    An app update on Motorola phones has started hijacking the Amazon app for the sake of injecting an affiliate code. To do that, tapping the app icon opens the user’s browser and immediately redirects to the Amazon app. It’s a “blink and you missed it” moment. This only happens when the user opens the Amazon app from the app drawer – not the homescreen pages.

    We verified on a Razr (2026) running an older Smart Feed v2.03.0056 that this does not happen. Our Razr Fold, with app version 2.03.0070, has started showing this behavior, so it’s the latest update that’s to blame for hijacking the user’s intent. We couldn’t replicate this on a Moto G Stylus (2026) running the same app version, though. Sideloading the app, for reasons unclear, doesn’t seem to trigger this behavior, as manually installing the updated version on the aforementioned Razr (2026) didn’t show the same behavior.

    In further digging, we noticed that the URL the phone opens up is “kira-abboud.com,” a website that references fashion influencer “@kirasfashionfinds.” Notably, this exact URL isn’t listed anywhere on Abboud’s social media, and the affiliate codes don’t match up either. The redirect coming from Motorola phones is using Amazona affiliate code “sramz-kff-008-20” which is completely different from any of the codes we saw from links shared by Abboud’s accounts and linked websites.

    • Passerby6497@lemmy.world
      link
      fedilink
      English
      arrow-up
      27
      ·
      8 hours ago

      That sounds more like a phone got hit with malware than it necessarily being Motorola doing it. The same version of the app on multiple systems or side loading the suspicious version didn’t trigger the behavior, so I’m doubtful the app itself is to blame.

      • atrielienz@lemmy.world
        link
        fedilink
        English
        arrow-up
        8
        ·
        7 hours ago

        Yeah but the app developer is Motorola. So unless they have had a breach (they’d like to tell us about) the call is coming from inside the house.

        • Passerby6497@lemmy.world
          link
          fedilink
          English
          arrow-up
          4
          ·
          5 hours ago

          If “the call is coming from inside the house”, why is it so specific/not very reproducible across the same app version and different methods of installing/accessing the app?

          • atrielienz@lemmy.world
            link
            fedilink
            English
            arrow-up
            3
            ·
            4 hours ago

            This is exactly why I said the bit about ‘unless there’s a breach’.

            There’s another comment on one of these threads that goes in depth about who the affiliate link supposedly belongs to, even though it doesn’t match any of their known affiliate links, and it would appear that the affiliate link doesn’t actually belong to Motorola (that anyone has been able to prove so far).

            All that being said, Motorola is the developer of the app so if they pushed an update that causes this, then they are on the hook. Whether or not they are behind the affiliate link or there’s some kind of MIM/malware or similar attack remains to be seen. Unfortunately we live in a time where app repos are being compromised left and right so with the limited information in the article this was my view of the situation.

            • Passerby6497@lemmy.world
              link
              fedilink
              English
              arrow-up
              2
              ·
              4 hours ago

              Whether or not they are behind the affiliate link or there’s some kind of MIM/malware or similar attack remains to be seen. Unfortunately we live in a time where app repos are being compromised left and right so with the limited information in the article this was my view of the situation.

              I understand what you’re saying, I’m saying the information we have doesn’t fit the behavior you’re equating this to.

              Given they only had the issue when accessing it via the moto app drawer app on a limited number of phones and didn’t see it when side loading or loading the app from another store, that is evidence against an app compromise and is closer to the behavior seen in local compromises. Were this an app level compromise as you’re suggesting, the behavior wouldn’t disappear on different devices or when side loaded.

              I could easily be wrong, I just don’t see the behavior I’d expect to see for a wide ranging own like a repo takeover.