Beware: Adobe Flash Is Under Siege!

Attackers are targeting both the traditional Adobe Flash application, and the recently pulled Flash for Android mobile app.

Adobe Flash has long been a prime target for hackers and malware developers. The virtually ubiquitous app seems to have plenty of weaknesses, and presents attackers with an appealing method of exploiting and compromising victims. Currently, both the traditional Adobe Flash, and the Adobe Flash for Android mobile app have caught the attention of attackers.Adobe Flash is a staple of Web browsing, and is essentially a de facto app installed on just about every Windows, Mac, and Linux PC. The mobile app has been a source of controversy between Apple and Adobefamously excluded from Apples iOS mobile platformhowever, Flash was trumpeted as a key selling point for rival Android devices.

Adobe released a new version of the traditional Flash software recently as a part of its regular quarterly update schedule. The update addressed security vulnerabilities in the software, but attackers still found holes to work with and Adobe quickly released yet another update for Flash a week later.

The current attacks against Flash involve a malicious Microsoft Word file attachment, which targets the ActiveX control for Flash in the Internet Explorer Web browser. Users should update to the most current version of Flash to guard against this threat, and both consumers and individuals should take advantage of the automatic updates feature in Adobe Flash to make sure the most recent updates are always installed.

On the mobile side, Flash may have been a good marketing tool as a knife to twist with customers weighing a decision between the two platforms, but the appeal quickly waned. Flash Mobile has been buggy, and performance has been flaky since its inception. Adobe recently announced it will no longer support Flash for Android, and the app was pulled from the official Google Play store.

The problem for users is that Adobe may not be supporting Flash for Android any longer, but that doesnt mean there arent versions available out there somewhere. One of the benefits of Android for many users is its openness, and the fact that apps can be downloaded from a diverse array of third-party sites outside of the official Google Play store.

Attackers know this as well, though, and take advantage of it. Preying on the popularity and demand for Adobe Flash, and the naiveté of average users, attackers have unleashed an avalanche of rogue and malicious apps that appear to be Flash or some suitable equivalent.

Some of the fake Flash apps are more nuisance than threatopening an app filled with ads, or redirecting users to a website with ads. Apps like these generate money for the attackers by surreptitiously forcing people to the ad sites, which in turn pay the attackers for the traffic. Some of the fake Flash apps are more insidious, thoughTrojan horse attacks that seem to be Flash but instead install malicious apps.

While it may seem like Adobe Flash itself is the problem, that isnt entirely the case. No software is perfect, and Adobe became a popular target more as a function of its success than its weaknessesthe fact that it is available on almost every platform and device makes it a sort of Holy Grail for attackers.

The lesson to take away, though, is not to avoid Adobe Flash. The lesson is that attackers are clever and will find ways to exploit popular third-party applications to circumvent security controls. You need to have a strong cross-device security solution to detect and block threats like these, and protect you from attacks.

Comments are now closed.
CSO Corporate Partners
  • Webroot
  • Trend Micro
  • NetIQ
rhs_login_lockGet exclusive access to CSO, invitation only events, reports & analysis.
CSO Directory

Secure Virtualization of Business Applications

Run your mission-critical applications in a secure and compliant virtual datacenter, or private cloud.

Security Awareness Tip

Incident handling is a vast topic, but here are a few tips for you to consider in your incident response. I hope you never have to use them, but the odds are at some point you will and I hope being ready saves you pain (or your job!).


  1. Have an incident response plan.

  2. Pre-define your incident response team 

  3. Define your approach: watch and learn or contain and recover.

  4. Pre-distribute call cards.

  5. Forensic and incident response data capture.

  6. Get your users on-side.

  7. Know how to report crimes and engage law enforcement. 

  8. Practice makes perfect.

For the full breakdown on this article

Security ABC Guides

Warning: Tips for secure mobile holiday shopping

I’m dating myself, but I remember when holiday shopping involved pouring through ads in the Sunday paper, placing actual phone calls from tethered land lines to research product stock and availability, and actually driving places to pick things up. Now, holiday shoppers can do all of that from a smartphone or tablet in a few seconds, but there are some security pitfalls to be aware of.