International Cyber Expo International Cyber Expo
  • About Us
Tuesday, 21 July, 2026
IT Security Guru
International Cyber Expo
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us
No Result
View All Result
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us
No Result
View All Result
IT Security Guru
No Result
View All Result

In-app security will play a key role in thwarting Cloak & Dagger vulnerability, says Promon

by The Gurus
May 30, 2017
in Editor's News
Share on FacebookShare on Twitter

The recent discovery of the Cloak & Dagger attack vector, which can steal personal information by mimicking the activities of apps, is indicative of the new level of sophistication that Android-targeted malware has reached. To increase the chances of defeating attacks of this nature, in-app security needs to move to the top of the agenda for any app-focused business. This is according to app security specialist Promon.
According to researchers at the Georgia Institute of Technology, Cloak & Dagger works by using Android’s design and screen behaviours against users, hiding activities such as keystroke recording, stealthy phishing and the enabling of app permissions behind seemingly innocuous screens. To combat such a dangerous strain of malware that can be so hard to detect, Promon believes that apps have a greater need than ever to be proactively protected, both during runtime and when they are idle.
Tom Lysemose Hansen, founder and CTO at Promon, said: “Cloak & Dagger is a particularly nasty example of Android malware, given its level of sophistication in being able to effectively steal information in a way that can be very difficult for users to notice. Due to its nature, it’s also likely to inspire copycat versions, so it certainly shouldn’t be treated as an isolated case.
“While it is possible to disable the exploit by turning off the ‘draw on top’ permission in a device’s settings, the stealthy nature of Cloak & Dagger makes fast, definitive action on the part of users unlikely. Instead, app developers need to think about what they themselves can do to guard against such a threat.”
Hansen believes that runtime application self-protection (RASP) software can be particularly useful in fighting malware of this nature.
He added: “RASP software is advantageous because it proactively detects and eliminates threats while an app is running. Malware such as Cloak & Dagger works by monitoring someone’s activity while they are using an app, so it is crucial that app protection is able to thwart attacks at this point.”
With the General Data Protection Regulation (GDPR) now less than a year away from implementation, Hansen also thinks that Cloak & Dagger should shine a spotlight on the urgent need for businesses to secure their mobile apps before GDPR comes into force.
He concluded: “Mobile threats are only going to increase in sophistication. At the same time, the stipulations of GDPR mean the financial penalties for experiencing a data breach will be particularly severe. The time to act is now, while the malware threat level is high, and there is still some time left to prepare for GDPR’s arrival.”

Tags: CyberdatasecurityTechnologyVulnerability
ShareTweet
Previous Post

Gartner Says Four Vectors Are Transforming the Security Software Market

Next Post

Brits say mobile apps are as important as breathing, eating and drinking

Recent News

What Does the Cyber Industry Want to See From the New UK Government?

What Does the Cyber Industry Want to See From the New UK Government?

July 20, 2026
Purple Logo, capitalised letters: SALT.

Salt Security tackles AI governance challenge with 100 pre-built agentic security policies

July 20, 2026
New Continuous Runtime Security Validation service aims to strengthen fintech cyber resilience

New Continuous Runtime Security Validation service aims to strengthen fintech cyber resilience

July 20, 2026
Scams Now Drive Almost Half of All Malware Detections as Attackers Weaponise Everyday Trust

Scams Now Drive Almost Half of All Malware Detections as Attackers Weaponise Everyday Trust

July 20, 2026

Eskenzi PR banner ad

The IT Security Guru offers a daily news digest of all the best breaking IT security news stories first thing in the morning! Rather than you having to trawl through all the news feeds to find out what’s cooking, you can quickly get everything you need from this site!

Our Address: 10 London Mews, London, W2 1HY

Follow Us

© 2015 - 2026 IT Security Guru - Website Managed by Dessol

  • About Us
Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}
No Result
View All Result
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us

© 2015 - 2026 IT Security Guru - Website Managed by Dessol