|
|
25 million Android devices get infected - TechAmok
25 million Android devices get infected - [security] 06:32 PM EDT - Jul,10 2019 - (3 comments) The name 'Agent Smith' is usually associated with the famed Matrix movie trilogy. However, it is now being used to identify a new variant of malware discovered by security provider Check Point Research. The firm reports that around 25 million Android devices have been infected by Agent Smith over the course of the last three years, and that the attackers behind the scenes may be looking to expand their reach.
The malware is spread through 9Apps, a third-party apps store, and has targeted mainly Asian users; however, countries such as the U.S. and U.K. have had a high amount of device breaches as well. Essentially, the life cycle of the malware revolves around three phases that have been described in the following way:
1) A dropper app lures victim to install itself voluntarily. The initial dropper has a weaponized Feng Shui Bundle as encrypted asset files. Dropper variants are usually barely functioning photo utility, games, or sex related apps.
2) The dropper automatically decrypts and installs its core malware APK which later conducts malicious patching and app updates. The core malware is usually disguised as Google Updater, Google Update for U or “com.google.vending”. The core malware's icon is hidden.
3) The core malware extracts the device's installed app list. If it finds apps on its prey list (hard-coded or sent from C&C server), it will extract the base APK of the target innocent app on the device, patch the APK with malicious ads modules, install the APK back and replace the original one as if it is an update.
To expand a bit upon each of these phases, 'droppers' are apps that imitate popular utilities while quietly installing malicious content on a device. The dropper variants deployed as part of this attack include a number of different applications that may attract users of all ages. These typically offer little to no functionality, but a one-time installation is all that's required to address a major phase of the attack - actually getting the malware on the target device.
Moving on, the core module of a 'loader' that's additionally coded with the dropper gets installed, and begins searching the infected device for pre-determined popular apps. The pre-determined list of apps is obtained through contact with a command-and-control (C&C) server. The apps include some highly popular and widely-used ones, such as WhatsApp, ShareIt, MX Player, the Opera browser and more. The loader then works with various other modules to infect the legitimate applications with its own code. As a result of this alteration, Android's package manager is duped into considering the malicious files as an update for said applications. Throughout the following 'update' process, the malware disguises itself as a Google-related updating tool, thus not rousing users' suspicions. The breached apps, now carrying the malicious ad modules patched into their APKS, start displaying these ads as a replacement of in-app activity. Even if said app isn't specified in the pre-created list, the ads are simply shown on any activity that is being loaded at the time. Notably, 'Agent Smith' will continue to infect the same device multiple times, whenever the latest malicious patches are available.
Based on its research, Check Point believes that a Chinese firm operating in the city of Guangzhou is the main culprit behind the attacks. The name of the company has been redacted from its publication, and information related to the attacks has been provided to law enforcement officials, as well as Google, to assist them in further investigation. Although this form of malware was initially only spread through 9Apps, the researchers discovered traces of the malicious actors looking to spread their system to Play Store applications as well. During the search, 11 Play Store apps were found to be connected to the attackers. However, Check Point does state that it has worked closely with Google to remove all of these from the Play Store.
Google has not issued a public statement regarding the matter as of yet, though we'll keep you updated. For now, do make sure that you download your applications from a trustworthy app store, and be on the lookout for ads that may crop up at unusual times. |
|
| (11:58 AM EDT - Jun,02 2020) - jackyj | | |
| (11:58 AM EDT - Jun,02 2020) - jackyj | | |
| (06:59 AM EDT - May,13 2020) - fazadoxe | The recent news break about the technology that there are millions of devices who are infected during the security breach. All this news is covering by uk essays review who provides the authentic news on all the technology. | |
Add your comment (free registrationrequired)
Short overview of recent news articles |
|
Mar,06 2026 Anthropic CEO Drops Bombshell: Claude AI Might Actually Be Conscious Mar,06 2026 Windows Update KB5077181 Sparks Gaming Stutter Crisis - Easy Fix Mar,06 2026 Google's 2025 Zero-Day Tally: 90 Exploits, Enterprise Under Siege, Mar,06 2026 Windows Secure Boot is EXPIRING: Do This Before June 2026! Mar,05 2026 Spy-Grade 'Coruna' Exploit Kit Now Fuels Mass Crypto Thefts on Mar,05 2026 Google Drops Urgent Chrome Patch: 10 Flaws Fixed in Critical Mar,05 2026 NVIDIA GeForce Hotfix Driver v595.76 is now available Mar,04 2026 Google Slashes App Store Fees and Opens Door to Third-Party Stores Mar,04 2026 Android's New Update Brings New Find My Features Mar,04 2026 Samsung Confirms DRAM Prices Surge Over 100% in Q1 2026 Amid Mar,04 2026 HW News - "Microslop" Censored, NVIDIA Unlaunches Drivers Again, Mar,04 2026 A €55 ITX Case! - DeepCool CH170 DIGITAL Review Mar,04 2026 Critical Flaw in MS-Agent AI Framework Exposes Systems to Remote Mar,04 2026 South Korean Tax Officials Fumble $4.8 Million in Seized Crypto Mar,03 2026 Windows 11 Upgrade Bug 'Deletes the Internet' for Some Users, Mar,03 2026 Open-Source AI 'Hacker' Shannon Explodes to Fame with 96% Exploit Mar,03 2026 Google Drops Massive Android Security Patch: Fixes 129 Flaws Mar,02 2026 Apple Unveils iPhone 17e: MagSafe, A19 Chip, and Double Storage at Mar,02 2026 NVIDIA GeForce 595.71 WHQL Driver Mar,02 2026 Russian-Linked APT28 Exploits Zero-Day in Legacy MSHTML Engine to Mar,02 2026 Honor Unveils Mind-Blowing Robot Phone with Dancing Camera at MWC Mar,02 2026 Resident Evil 9 Requiem - Bonus DLC Mar,01 2026 Microsoft's Copilot Discord Server Locked Amid 'Microslop' Spam Mar,01 2026 Anghami CEO Open-Sources Powerful Real-Time Global War Monitor Mar,01 2026 Chinese Developers Unleash Blazing-Fast Android AI Agent with Mar,01 2026 Claude Surges to #1 on App Store as ChatGPT Faces Boycott Backlash Feb,28 2026 Google Reveals Key New Features of Android 17 Feb,28 2026 OLED Gaming Monitors Are Finally Affordable Feb,28 2026 OpenAI's KYC Partner Exposed in Surveillance Scandal as ChatGPT Feb,28 2026 Pentagon Blacklists Anthropic Over AI Safeguards; OpenAI Secures Feb,27 2026 Have RAM and GPU Prices Peaked? Feb,27 2026 Zoom 'Update' Trap: Fake Site Infects 1,437 Users with Spyware in Feb,27 2026 Stop WASTING Money on Fancy RAM Feb,27 2026 Drunk AI robot Feb,26 2026 AirSnitch Exposes Critical Flaw: Wi-Fi Client Isolation Broken in Feb,26 2026 Revolutionary Ultrasonic Knife Hits Kitchens: C-200 Vibrates for Feb,26 2026 Apple Scores Historic NATO Security Clearance: iPhone and iPad First Feb,26 2026 Kali Linux Goes AI-Powered: Claude Now Runs Your Pen Tests in Plain Feb,26 2026 Resident Evil Requiem - Stunning on PS5 Pro + PS5/Xbox Series X|S Feb,26 2026 Samsung Galaxy S26 Ultra Flexes Hardware Muscle Over iPhone 17 Pro
>> News Archive <<
| |
|