Security researchers find multistage Android malware on Google Play
- 11 July, 2012 18:15
- Comments
Security researchers from antivirus vendor Symantec identified two malware apps on Google Play that used a multistage payload delivery system in order to remain undetected.
The apps, which have since been removed by Google, masqueraded as two games -- "Super Mario Bros." and "GTA 3 - Moscow city."
"Both were posted to Google Play on June 24 and since then have generated in the range of 50,000 to 100,000 downloads," Symantec security researcher Irfan Asrar said Tuesday in a blog post.
Once installed, the apps downloaded an additional package called Activator.apk from a Dropbox account and prompted the device owners to install it.
This secondary Activator app sent SMS messages to a premium-rate number located in Eastern Europe, after which it asked to be uninstalled.
The fact that the malicious payload was delivered in multiple stages is probably why the apps managed to remain undetected for so long on Google Play, Asrar said.
Earlier this year, Google started using an automated scanner called Bouncer to detect malware on Google Play. Bouncer runs all published apps in an emulated Android environment and monitors them for suspicious activity.
However, downloading a secondary app from a developer's server and prompting the user to install it might not necessarily represent malicious behavior.
This is not the first time when Android malware developers have used multi-stage payloads. The Android.Lightdd and Android.Jsmshider threats discovered in 2011 both downloaded additional components after the installation of an initial app.
There are several advantages to spreading the payload across multiple apps, Asrar said about those threats at the time. For one, the initial malicious app no longer needs to display an extensive list of permissions that might attract the user's attention.
Secondly, if the initial app is downloaded from the official Android marketplace -- now called Google Play -- the user is likely to assume that the additional apps also originate from there.
Symantec detects the two newly found malware apps as Android.Dropdialer. The Android security team immediately removed the threat after being notified by Symantec, Asrar said.
Join the CIO Australia group on LinkedIn. The group is open to CIOs, IT Directors, COOs, CTOs and senior IT managers.
- Bookmark this page
- Share this article
- Got more on this story? Email CIO
- Follow CIO on twitter
-
Solving the skills conundrum – part 1
-
Australia suspected to have PRISM data: Ludlam
-
Australia Post’s mail business to lose $200 million this year
-
Australia Post’s mail business to lose $200 million this year
-
Microsoft's ambivalence about Office on the Web gives Apple shot with iWork on iCloud
-
Spear-Phishing Email: Most Favored APT Attack Bait
This research paper presents findings on APT-related spear phishing from February to September 2012. We analysed APT-related spear-phishing emails collected throughout this period to understand and mitigate attacks. The information we gathered not only allowed us to obtain specific details on spear phishing but also on targeted attacks. We found, for instance, that 91% of targeted attacks involve spear-phishing emails, reinforcing the belief that spear phishing is a primary means by which APT attackers infiltrate target networks. -
Choice and Control – Considerations for Developing Enterprise Cloud Strategies
Enterprise-wide cloud implementation can be a challenging process, requiring a thoughtful, strategic approach. In this whitepaper, IBM® shares considerations for developing enterprise cloud strategies. It looks into how the rapid-scale enterprise-class environment can help enable the type of agile infrastructure that aids organisations in quickly meeting the demands of an ever-evolving marketplace, thereby providing true business value. Read now. -
McAfee Complete Endpoint Protection - Business
McAfee makes endpoint security painless for users and easy and efficient for IT. Built for strength, speed, and simplicity, McAfee Complete Endpoint Protection - Business suite helps growing organisations get Internet security right, from turnkey installation to rapid response. Find out more.
















