Showing posts with label Trojan. Show all posts
Showing posts with label Trojan. Show all posts

Friday

New Trojan targets Android, infects 350K devices


Owners of mobile devices running Google's Android operating system were warned against a new Trojan that launches in the early loading stage and resides in the machine's memory.

Russian anti-virus company Doctor Web said the malignant program is operating on more than 350,000 mobile devices in countries including some in Southeast Asia.

"When the mobile phone is turned on, (a) script loads the code of the Trojan Linux-library imei_chk (Dr.Web Anti-virus detects it as Android.Oldboot.1), which extracts the files libgooglekernel.so (Android.Oldboot.2) and GoogleKernel.apk (Android.Oldboot.1.origin) and places them in /system/lib and /system/app, respectively," the company said in a blog post.

Doctor Web said its statistics show 92 percent of the compromised devices are in China, "which is not surprising, since the Trojan Android.Oldboot is intended for Android-powered devices in China."

It noted part of the Trojan Android.Oldboot is installed as a typical application which functions as a system service and connects to a remote server to await various commands.

"Reflashing a device with modified firmware that contains the routines required for the Trojan’s operation is the most likely way this threat is introduced," it said.

Doctor Web warned this malware is dangerous as even if some elements of Android.Oldboot are removed, the component imei_chk will still reside in the protected memory area and will re-install the malware after a reboot.

To prevent infection, Doctor Web advised users against buying devices "of unknown origin" and using OS images from unreliable sources. — VC, GMA News

source: gmanetwork.com

Saturday

Beware of malware posing as WhatsApp for PC


Users of desktop computers and laptops may want to think twice before downloading and installing a supposed PC version of the popular mobile app WhatsApp.

Security vendor Kaspersky Labs said, emails spreading online claim WhatsApp for PC is available and that the recipient already has 11 invitations from friends in his account.

"If the victim clicks on the link, it will lead him/her to a hacked server in Turkey and will then be redirected to a Hightail (Yousendit) account to download the initial Trojan, which in the system looks like a 64-bit installation file," Kaspersky researcher Dmitry Bestuzhev said in a blog post.

But the malware in reality will download a new Trojan that targets banking data.

According to Bestuzhev, the malware comes from a server in Brazil, with the recently downloaded banker having the icon of an mp3 file.

The malware also has some anti-debugging features to make analysis harder.

"Once running, the malware reports itself to the cybercriminals’ infections statistics console and when open, a local port 1157 sends stolen information in the Oracle DB format. In addition, it downloads new malware into the system; some samples are 10Mb in size. This is the classic style of a Brazilian-created malware," Bestuzhev said. — KDM, GMA News

source: gmanetwork.com