Critical.
Authoritative.
Strategic.
Subscribe to CIO Magazine »

Exploit-powered Android Trojan uses update attack

A new DroidKungFu variant poses as a legit application update

A new variant of the DroidKungFu Android Trojan is posing as a legitimate application update in order to infect handsets, according to security researchers from Finnish antivirus vendor F-Secure.

Distributing Android malware as updates is a relatively new tactic that was first seen in July. The primary method of infecting handsets continues to be the bundling of Trojans with legitimate applications; however, the resulting apps are easy to spot because of the extensive permissions they request at installation time.

According to security researchers, the new update-based attacks can have a higher success rate than "Trojanizing" apps, because users don't tend to question the legitimacy of updates for already-installed software.

Furthermore, when used by threats like DroidKungFu, update attacks can be hard to detect without specialized antimalware tools. That's because these Trojans use Android exploits to gain root access and then deploy their malicious components unhindered.

The new DroidKungFu variant is distributed with the help of a non-malicious application currently available from third-party app stores in China. However, the threat is global because apps infected with earlier versions of the Trojan have been detected on the official Android Market in the past.

"Once installed, the application would inform the user that an update is available; when the user installs this update, the updated application would then contain extra functionalities, similar to that found in DroidKungFu malware," the F-Secure researchers warn.

The update only asks for access to SMS/MMS messages and location, but also contains a root exploit for Android 2.2 (Froyo) that unlocks all system files and functions. Even though this particular DroidKungFu variant doesn't target devices running Android 2.3 (Gingerbread), there are other Trojans that infect this version of the operating system and could adopt the same attack technique in the future.

In addition, there is reason to believe that the malware's authors are also testing other infection methodologies. Last week, security researchers from mobile antivirus vendor Lookout detected another DroidKungFu variant that doesn't use root exploits at all.

Instead, the new Trojan, which Lookout calls LeNa, uses social engineering to trick users into giving the installer super-user access on devices where users have knowingly executed a root exploit. Once deployed, the malware attaches itself to a native system process.

"This is the first time an Android Trojan has relied fully on a native ELF binary as opposed to a typical VM-based Android application," the researchers explained. The malware is distributed by rogue VPN (virtual-private-network) applications, some of which were found on the official Android Market.

Join the CIO Australia group on LinkedIn. The group is open to CIOs, IT Directors, COOs, CTOs and senior IT managers.

More about: etwork, F-Secure
References show all

Comments

Post new comment

The content of this field is kept private and will not be shown publicly.
Users posting comments agree to the CIO comments policy.
Login or register to link comments to your user profile, or you may also post a comment without being logged in.
Related Coverage
Related Whitepapers
Latest Stories
Community Comments
Tags: Access control and authentication, data protection, Desktop security, Exploits / vulnerabilities, f-secure, malware, security
Latest Blog Posts
Whitepapers
  • Reconciling Datacenter consolidation and security: It starts with an integrated approach
    There is no question that datacenter consolidation has gone mainstream. A recent IDG Research survey of IT managers found that three out of four organizations are in the midst of, or just completing, consolidation of multiple applications or systems onto a smaller number of servers. Improving performance and availability was the key driver of consolidation efforts for 85% of those surveyed.
    Learn more »
  • Implementing Energy Efficient Data Centres
    Electrical power usage is not a typical design criterion for data centers, nor is it effectively managed as an expense. This is true despite the fact that the electrical power costs over the life of a data center may exceed the costs of the electrical power system including the UPS, and also may exceed the cost of the IT equipment. Read on.
    Learn more »
  • The Top 5 Server Monitoring Battles—and How You Can Win Them
    The role of servers in your organization has changed substantially—with their uses, requirements, and complexity all increasing dramatically in recent years. Many of the traditional tools and techniques that worked in the past don’t suffice any more. Consequently, server monitoring presents several critical battles in today’s demanding environments. This guide looks at some of the most pressing challenges administrators face in ensuring optimal server performance, and it offers insights into the tools and strategies required to address these demands.
    Learn more »
All whitepapers
rhs_login_lockGet exclusive access to Invitation only events CIO, reports & analysis.
Recent comments