The Mother Of All Android Malware Has Arrived

Status
Not open for further replies.

Jack

Administrator
Thread author
Verified
Staff Member
Well-known
Jan 24, 2011
9,378
The Mother Of All Android Malware Has Arrived: Stolen Apps Released To The Market That Root Your Phone, Steal Your Data, And Open Backdoor

Openness – the very characteristic of Android that makes us love it – is a double-edged sword. Redditor lompolo has stumbled upon a perfect example of that fact; he’s noticed that a publisher has taken "… 21 popular free apps from the market, injected root exploits into them and republished." The really scary part? "50k-200k downloads combined in 4 days."

Lompolo explains the situation quite well:

Link to publishers apps here. I just randomly stumbled into one of the apps, recognized it and noticed that the publisher wasn’t who it was supposed to be.

Super Guitar Solo for example is originally Guitar Solo Lite. I downloaded two of the apps and extracted the APK’s, they both contain what seems to be the "rageagainstthecage" root exploit – binary contains string "CVE-2010-EASY Android local root exploit (C) 2010 by 743C". Don’t know what the apps actually do, but can’t be good.

I appreciate being able to publish an update to an app and the update going live instantly, but this is a bit scary. Some sort of moderation, or at least quicker reaction to malware complaints would be nice.

EDIT: After some dexing and jaxing, the apps seem to be at least posting the IMEI and IMSI codes to http://184.105.245.17:8080/GMServer/GMServlet, which seems to be located in Fremont, CA.


apps_by_myournet_thumb.png


More details - link

Update: The publisher’s been removed entirely from the market, so you can no longer see the list of apps. Luckily, I managed to grab a few screenshots last night. There’s been a ton of response to this, and we’ve been contacted by a few big dogs. Justin is also working on a removal tool. I’ll be doing a follow-up post this evening.
 

AyeAyeCaptain

Level 1
Feb 24, 2011
585
We all knew this would come sometime, as the more popular it gets the more open/inclined people are to attack. There is not enough security within the android from stock in the first place, and its quite shocking how easy it can be done. Do you think this will push more and more security vendors to push out reliable solutions to this problem?

I'm sure it will be the case soon enough, where vendors pay the makers of phone to have their stuff bundled with the phones?
 

LaserWraith

Level 1
Feb 24, 2011
497
I've always thought it would be nice to have some security apps like we have for PCs. Would this be possible?
 
Status
Not open for further replies.

About us

  • MalwareTips is a community-driven platform providing the latest information and resources on malware and cyber threats. Our team of experienced professionals and passionate volunteers work to keep the internet safe and secure. We provide accurate, up-to-date information and strive to build a strong and supportive community dedicated to cybersecurity.

User Menu

Follow us

Follow us on Facebook or Twitter to know first about the latest cybersecurity incidents and malware threats.

Top