Showing posts with label Android Malware Scam. Show all posts
Showing posts with label Android Malware Scam. Show all posts
Friday
New Trojan targets Android, infects 350K devices
Owners of mobile devices running Google's Android operating system were warned against a new Trojan that launches in the early loading stage and resides in the machine's memory.
Russian anti-virus company Doctor Web said the malignant program is operating on more than 350,000 mobile devices in countries including some in Southeast Asia.
"When the mobile phone is turned on, (a) script loads the code of the Trojan Linux-library imei_chk (Dr.Web Anti-virus detects it as Android.Oldboot.1), which extracts the files libgooglekernel.so (Android.Oldboot.2) and GoogleKernel.apk (Android.Oldboot.1.origin) and places them in /system/lib and /system/app, respectively," the company said in a blog post.
Doctor Web said its statistics show 92 percent of the compromised devices are in China, "which is not surprising, since the Trojan Android.Oldboot is intended for Android-powered devices in China."
It noted part of the Trojan Android.Oldboot is installed as a typical application which functions as a system service and connects to a remote server to await various commands.
"Reflashing a device with modified firmware that contains the routines required for the Trojan’s operation is the most likely way this threat is introduced," it said.
Doctor Web warned this malware is dangerous as even if some elements of Android.Oldboot are removed, the component imei_chk will still reside in the protected memory area and will re-install the malware after a reboot.
To prevent infection, Doctor Web advised users against buying devices "of unknown origin" and using OS images from unreliable sources. — VC, GMA News
source: gmanetwork.com
Sunday
Android trojan steals banking data, targets Korean users
A new Android Trojan that steals banking data is making the rounds online and is presently targeting Korean users, a security vendor reported this week.
MalwareBytes said the Trojan disguises itself as the Google Play Store app, then replace legitimate banking apps and capture user data.
"This particular one disguises itself as the Google Play Store app and will run as a service in the background to monitor events. This enables it to capture incoming SMS, monitor installed apps and communicate with a remote server," it said in a blog post.
It added this appears to be the latest variant of Android banking Trojans that previously targeted European and Brazilian banks.
MalwareBytes said malware authors appear to be expanding into other markets, "since Android is very popular worldwide."
An investigation showed the Trojan will contain the exact Package Name and look very similar to the legitimate app, "but contains malicious code with no banking functionality."
It will "capture the infected users banking information and other useful data that will generate revenue for them," it added.
MalwareBytes advised users to "stick to reputable markets for your apps and be wary of downloading apps from file shares, especially if one is available in the Play Store." — KDM, GMA News
source: gmanetwork.com
Saturday
Beware of Android malware scam promising antivirus
Users of mobile devices running Google's Android were warned over the weekend against a new "malvertising" scam that promises an antivirus but instead subscribes them to premium ringtone and wallpaper services.
Security vendor Bitdefender said a banner delivered by an advertising SDK included in some legitimate apps was deploying a scareware-type attack.
"When users download an app containing the advertising module delivering this scam, an alarmist banner pops-up out of the blue on the handset screen, making users believe their devices are infected with malware and prompts them towards purchasing a useless disinfection tool," Bitdefender's Loredana Botezatu said in a blog post.
However, she said the providers of the advertising module may not be aware their service is delivering a malicious banner, and that it could have been "an invalidated ad that accidentally reached the market."
Botezatu said the scam involves a sudden pop-up message on Android devices, suggesting the device was infected with malware.
It then tells owners to test their devices for possible malware. When tapped, the ad redirects users to a web page that tells them to download a disinfection tool.
The user is told to enter his or her phone number in a form, then press Download, Botezatu said.
"But instead of getting the Android device cleaned up, they get signed up with a premium-rate ringtone and wallpaper service that charges €3.00 per week plus taxes until the user unsubscribes manually," she added.
Botezatu also said the webpage redirects are based on geolocation, "so the premium service partner is chosen from the ones available in the victim’s location."
This means that if a user in Spain installs the app, he will receive messages written Spanish, and if the user is in Germany or Australia, the banners will be in German and English, respectively, she said.
Botezatu advised Android users to unsubscribe immediately by sending a SMS message to the number in the "Terms and Conditions" section of the website.
She also suggested that the user "uninstall immediately the apps you downloaded recently." – KDM, GMA News
source: gmanetwork.com
Labels:
Android,
Android Malware Scam,
Bitdefender,
Google,
Google Android,
Malware,
Tech News,
Technology,
World News
Subscribe to:
Posts (Atom)



