Phishing Attacks on Modern Android
Simone Aonzo, Alessio Merlo, Giulio Tavella, Yanick Fratantonio
Abstract
Modern versions of Android have introduced a number of features in the name of convenience. This paper shows how two of these features, mobile password managers and Instant Apps, can be abused to make phishing attacks that are significantly more practical than existing ones. We have studied the leading password managers for mobile and we uncovered a number of design issues that leave them open to attacks. For example, we show it is possible to trick password managers into auto-suggesting credentials associated with arbitrary attacker-chosen websites. We then show how an attacker can abuse the recently introduced Instant Apps technology to allow a remote attacker to gain full UI control and, by abusing password managers, to implement an end-to-end phishing attack requiring only few user's clicks. We also found that mobile password managers are vulnerable to "hidden fields" attacks, which makes these attacks even more practical and problematic. We conclude this paper by proposing a new secure-by-design API that avoids common errors and we show that the secure implementation of autofill functionality will require a community-wide effort, which this work hopes to inspire.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 2c346fc9-96e9-4bb8-a293-c7b1cfd5be0cCited by top-tier papers20
- SoK: Authentication in Augmented and Virtual RealitySophie Stephenson, Bijeeta Pal, Stephen Fan, Earlence Fernandes et al.S&P 2022 · 76 citations
- Demystifying Resource Management Risks in Emerging Mobile App-in-App EcosystemsHaoran Lu, Luyi Xing, Yue Xiao, Yifan Zhang et al.CCS 2020 · 48 citations
- Less Defined Knowledge and More True Alarms: Reference-based Phishing Detection without a Pre-defined Reference ListRuofan Liu, Yun Lin, Xiwen Teoh, Gongshen Liu et al.USENIX Security 2024 · 39 citations
- When the User Is Inside the User Interface: An Empirical Study of UI Security Properties in Augmented RealityKaiming Cheng, Arkaprabha Bhattacharya, Michelle Lin, Jaewook Lee et al.USENIX Security 2024 · 29 citations
- All your app links are belong to us: understanding the threats of instant apps based attacksYutian Tang, Yulei Sui, Haoyu Wang, Xiapu Luo et al.FSE 2020 · 22 citations
Builds on1
Related papers
- Vault Raider: Stealthy UI-based Attacks Against Password Managers in Desktop EnvironmentsAndrea Infantino, Mir Masood Ali, Kostas Solomos, Jason PolakisNDSS 2026 · 1 citation
- AutoFail: Breaking Web Boundaries using Android's Autofill FrameworkRiccardo Lamarca, Philipp Beer, Marco SquarcinaUSENIX Security 2026
- Phishing Attacks against Password Manager Browser ExtensionsClaudio Anliker, Daniele Lain, Srdjan CapkunUSENIX Security 2025
- Total Recall: Persistence of Passwords in AndroidJaeho Lee, Ang Chen, Dan S. WallachNDSS 2019 · 11 citations
- Exploiting Leakage in Password Managers via Injection AttacksAndrés Fábrega, Armin Namavari, Rachit Agarwal, Ben Nassi et al.USENIX Security 2024 · 1 citation
