Showing posts with label Android News. Show all posts
Showing posts with label Android News. Show all posts
Saturday, June 8, 2013
Android malware discovered, most advanced yet claims researchers
Security researchers have discovered what is claimed to be the most sophisticated Android malware ever seen.
![]() |
| Android malware discovered, most advanced yet claims researchers |
Dubbed Obad,
the malware can send texts to premium rate numbers, download and
install additional malware and remotely execute console commands. It
also uses complex obfuscation techniques to evade detection.
The malware was unearthed by researchers working for IT security firm
Kaspersky said that once the smartphone is infected, the malware
quickly gains access to privileges on the phone and starts working in
the background. The Trojan then attempts to spread through Wi-Fi and
Bluetooth networks sending malicious files to other phones.
Obad also exploits vulnerabilities in the Android OS. It can gain
administrator privileges, making it virtually impossible for a user to
delete it off a device. Another flaw in the Android OS relates to the
processing of the AndroidManifest.xml file. This file exists in every
Android application and is used to describe the application’s structure,
define its launch parameters.
"The malware modifies AndroidManifest.xml in such a way that it does
not comply with Google standards, but is still correctly processed on a
smartphone thanks to the exploitation of the identified vulnerability,"
said Roman Unuchek, Kaspersky Lab Expert. "All of this made it extremely
difficult to run dynamic analysis on this Trojan."
It also interferes with DEX2JAR code on the device, this converts APK
files into JAR files. The disruption complicates analysis of the
Trojan.
The Trojan collects large amounts of data from the device, which it
passes back to hackers through a command and control (C&C) server,
according to Unuchek. The collected information is sent to the server in
the form of an encrypted JSON object.
This information is sent to the current C&C server every time a
connection is established. In addition, the malicious program reports
its current status to its owner: it sends the current table of premium
numbers and prefixes to which to send text messages, the task list, and
the list of C&C servers. During the first C&C communication
session, it sends a blank table and a list of C&C addresses that
were decrypted as described above. During the communication session, the
Trojan may receive an updated table of premium numbers and a new list
of C&C addresses.
Unuchek said that the malware "looks closer to Windows malware than
to other Android Trojans, in terms of its complexity and the number of
unpublished vulnerabilities it exploits."
"This means that the complexity of Android malware programs is growing rapidly alongside their numbers," he said.
Sunday, May 26, 2013
New Android Virus Forwards Messages To Hackers
A new Trojan malware
infecting Android phones is capable of intercepting inbound text
messages and forwarding them to hackers. The malware, called
Android.Pincer.2.origin, is particularly troubling because it can easily
thwart the two-step verification systems employed by online banking,
email and social media accounts.
The malware, discovered by Russian antivirus company Doctor Web,
spreads as a fake security certificate that tricks users into thinking
they need to install it on their Android phones. After installation,
users will get a notification that installation was successful, but the
malware won’t do any other noticeable activities. It will instead run in
the background, connecting to a remote server to send information about
the user's Android device, including model and serial number, carrier
information, phone number and operating system.![]() |
| A new virus infects Android phones, forwarding text messages to hackers. |
![]() |
| A new virus infects Android phones, forwarding text messages to hackers. |
![]() |
| A new virus infects Android phones, forwarding text messages to hackers. |
Once connected, hackers can send the malware instructions to intercept and forward messages from specific phone numbers, send new text messages, display a message on the Android device’s screen, and other deceptive activities.
The ability to specify a phone number from which to intercept messages allows a hacker to use the malware for targeted attacks, stealing only specific messages that contain valuable information. For example, the hacker could set the malware to forward texts received from banking services.
Two-step verification systems often use cellphone messaging to verify a user’s identity. The user registers his or her phone number with the service, and when they attempt to log in to their account, the service sends a text message with the password. The user must then use this password to complete the login.
The system, which Kim Dotcom claimed Thursday to have invented, is designed to protect against phishing scams that use malware to send hackers the login information. When an account requires a second password that is randomized each time and sent to a device that only the user has access to, not even a hacker with access to the primary user name and password can access it. Twitter announced a two-step verification system on Wednesday after hackers compromised several high-profile Twitter accounts.
But if a hacker has access to cellphone messages and can set the malware to forward every message sent from Twitter or a bank, they could get that password and access to the account. Stay on the lookout and be careful to install software only from trusted sources.
Saturday, December 29, 2012
New Android Malicious Program helps to mount DDOS Attack
The Russian antivirus vendor Doctor Web has found a new Android malicious program. Which allows hacker groups to carry out Distributed-denial-of-service(DDOS) attacks. It is also capable of sending sms based on the command received from the hacker.

This malicious program works in the background without your knowledge. Once it is installed it will get activated and program will start searching for its command and control center and sends out information about your device there.
Dubbed theAndroid.DDoS.1.origin, creates an application icon, similar to that of Google Play. If the user decides to use the fake icon to access Google Play, the application will be launched and once the malicious program is launched, it transmits the victim's phone number to hackers and then waits for next SMS instruction from hackers.
For further details click here
Tuesday, November 6, 2012
Ethiopian Kids Hacked OLPCs in Five Month with zero Instructions
About five months ago, OLPC Project decided to have a little experiment. They chose a village in Ethiopia where the literacy rate was nearly 0% and decided to drop off a bunch of Motorola Xooms there. On the tablets, there was custom software that was meant to teach kids how to read. The kicker is that they gave no instructions. They just dropped the box off at town square and walked away.
The devices in use were Motorola Zoom tablets—used together with a solar charging system, which OLPC workers had taught adults in the village to use. OLPC workers would swap the memory cards in the systems and analyze them to understand what the machines were being used for.
OLPC founder Nicholas Negroponte at MIT Technology Review's EmTech conference last week: "We left the boxes in the village. Closed. Taped shut. No instruction, no human being. I thought, the kids will play with the boxes! Within four minutes, one kid not only opened the box, but found the on/off switch. He'd never seen an on/off switch. He powered it up. Within five days, they were using 47 apps per child per day. Within two weeks, they were singing ABC songs [in English] in the village. And within five months, they had hacked Android. Some idiot in our organization or in the Media Lab had disabled the camera! And they figured out it had a camera, and they hacked Android."
Timeline of Expirement
Within Four Minutes - One kid had opened the box and had figured out how to turn on the Xoom. within Five Days - The kids were using nearly 50 applications each every day. In Two Weeks - The kids were singing their ABC’s in English. now its 5th Month - They hacked the Motorola Xooms so they could enable the camera, which had been disabled by OLPC.
Subscribe to:
Posts (Atom)




