Mobile // Mobile Devices
News
5/3/2012
02:28 PM
Connect Directly
Twitter
Facebook
Google+
LinkedIn
RSS
E-Mail
50%
50%

New Drive-By Android Trojan Attacks Mobile Users

A new Trojan masquerating as a Google Android security update can automatically download and prompt the user to install it, .

Symantec has identified a threat known as Android.Notcompatible, an Android Trojan horse program that installs via a partial drive-by download. However, Symantec gives Android.Notcompatible its lowest risk level: Very Low. The main concern is that other hackers might copy the technique to use in other attacks.

Drive-by downloads--malware that installs itself without the user's knowledge--typically occur when you visit a website. Android.Notcompatible masquerades as an Android system update named "com.Security.Update". The download and installation sequence is demonstrated in the images below. Infected users approve the installation because they are fooled into thinking the program is a genuine update. Once installed on a phone, Android.Notcompatible uses proxy code to monitor all data moving in or out of the phone, including personal data, and copies it to the attacker.

Android.Notcompatible spreads via URL redirects injected into the HTML of innocent bystander sites. Devices that allow installation from unknown sources are most susceptible. Users who restrict their app downloads to Google Play are unlikely to encounter this or any other threat.

Symantec has identified the following sites as Android.Notcompatible hosts. (The "http" part of the addresses is bracketed to prevent accidental launches of infected sites.):

  • [http://]androidbia.info
  • [http://]androidjea.info
  • [http://]gaoanalitics.info
  • [http://]androidonlinefix.info

Comment  | 
Print  | 
More Insights
Building A Mobile Business Mindset
Building A Mobile Business Mindset
Among 688 respondents, 46% have deployed mobile apps, with an additional 24% planning to in the next year. Soon all apps will look like mobile apps – and it's past time for those with no plans to get cracking.
Register for InformationWeek Newsletters
White Papers
Current Issue
InformationWeek Tech Digest - August 20, 2014
CIOs need people who know the ins and outs of cloud software stacks and security, and, most of all, can break through cultural resistance.
Flash Poll
Video
Slideshows
Twitter Feed
InformationWeek Radio
Sponsored Live Streaming Video
Everything You've Been Told About Mobility Is Wrong
Attend this video symposium with Sean Wisdom, Global Director of Mobility Solutions, and learn about how you can harness powerful new products to mobilize your business potential.