guardianproject / orbot

The Github home of Orbot: Tor on Android (Also available on gitlab!)
https://gitlab.com/guardianproject/orbot
Other
1.98k stars 325 forks source link

[BUG] android/spy. Agent. Dfm malware #1107

Open 1anonyy opened 2 months ago

1anonyy commented 2 months ago

My antivirus picked up a problem, I've had this app installed for a year. See picture.

Please advise Screenshot_20240312_210110_ESET Mobile Security

n8fr8 commented 2 months ago

It is a false positive from the antivirus maker.

However, if you want to be sure you have the authentic release signed by us, you can download the latest direct APK from here: https://github.com/guardianproject/orbot/releases/download/17.2.1-RC-1-tor-0.4.8.7/Orbot-17.2.1-RC-1-tor-0.4.8.7-fullperm-arm64-v8a-release.apk

1anonyy commented 2 months ago

It's from play store. Not anywhere else

On Wed, 13 Mar 2024, 02:47 Nathan Freitas, @.***> wrote:

It is a false positive from the antivirus maker.

However, if you want to be sure you have the authentic release signed by us, you can download the latest direct APK from here: https://github.com/guardianproject/orbot/releases/download/17.2.1-RC-1-tor-0.4.8.7/Orbot-17.2.1-RC-1-tor-0.4.8.7-fullperm-arm64-v8a-release.apk

— Reply to this email directly, view it on GitHub https://github.com/guardianproject/orbot/issues/1107#issuecomment-1993219883, or unsubscribe https://github.com/notifications/unsubscribe-auth/AES7BRDAXWKYL4GZLGR36ATYX644JAVCNFSM6AAAAABETHKKBGVHI2DSMVQWIX3LMV43OSLTON2WKQ3PNVWWK3TUHMYTSOJTGIYTSOBYGM . You are receiving this because you authored the thread.Message ID: @.***>

Hexag0nSun commented 1 month ago

I sent this to ESET marking it as False Positive, and their tech support insisted that part of Orbot code indeed can be used as a trojan. Despite it being the official tech support channel, the signatures make it clear it's the local reseller also doing tech support outsourcing, so I'm still waiting for confirmation on whether it's the official ESET statement on the matter.