Android Trojan Emerges In U.S. Download Sites
Games infected with botnet-like Geinimi attack code have spread to third-party U.S. and European sites as well as BitTorrent hosted collections, finds Symantec.Mobile security firm Lookout discovered the malware last week, noting that legitimate games such as Monkey Jump 2, President vs. Aliens, and Baseball Superstars 2010 had been modified with the Trojan to request many more permissions than the original games required. Lookout said the software was available from third-party Android app stores located in China.
More Hardware Insights
Webcasts
- Powering your Business with IBM's New 2s General Purpose Servers
- Protecting End Users Against Emerging Threats
White Papers
- ComputerWorld Tech Dossier: HP ProLiant DL360p & DL380p Gen8 Severs: Power, Flexibility & Serviceability
- Virtualizing Tier 1 Applications: A Critical Step on the Journey Toward the Private Cloud
Reports
More >>But on Wednesday, Symantec researcher Irfan Asrar said that "samples of the threat have found their way into North American and European hosted download sites as well in BitTorrent hosted collections of pirated games." He said that the attack still appeared designed to target Chinese Android smartphones, and that servers used to receive stolen data were still located in that region. What likely happened, he said, is that the original modified applications, which are popular, were simply picked up by other sites.
Asrar said that the Geinimi malware itself isn't revolutionary, per se, though it does a good job of applying innate Android capabilities for attack purposes. "A detailed analysis of this threat serves more as a testament to the ease of developing sophisticated code on a platform with good framework support than it does to establish any groundbreaking threat vectors," he said.
But the Android attack code is still effective. In particular, Asrar said that Geinimi can process more than 20 commands, connect with 11 different Web sites -- their locations were encrypted using DES -- and has its code obfuscated to make signature-based detection and reverse-engineering difficult.
"This does hint of an evolution in the Android threat landscape," he said.
Users of third-party download sites or pirated software are at risk, while Android Market users are not, because while the real and modified apps may look the same to end users, their underlying package names actually differ. Since Google requires package names to remain consistent from one version of an application to another -- so that it can accurately issue updates or revoke applications -- the modified code wouldn't pass muster, said Asrar.
InformationWeek has published an in-depth report on hardening next-gen Web applications. Download it now (free registration required).
Related Reading
| To upload an avatar photo, first complete your Disqus profile. | View the list of supported HTML tags you can use to style comments. | Please read our commenting policy. |
Subscribe to RSSResource Links
Related Webcasts
- SMB Server Guide: Meeting Email, Virtualization, and Business Application Challenges
- Powering your Business with IBM's New 2s General Purpose Servers
- Protecting End Users Against Emerging Threats
- CTO to CTO: Scott Davies, VMware, and Jim Davies, Mitel, Give Voice to the Virtual Desktop
- Server Virtualization Gets Relief From Tivoli Storage Manager for Virtual Environments
This Week's Issue
Free Print Subscription
SubscribeCurrent Healthcare Issue
- InformationWeek Healthcare CIO 25: Our second annual honor roll of the health IT leaders driving healthcare's transformation.
- EHR Unreadiness: Only a small percentage of physicians planning to apply for Meaningful Use funds have e-health record systems capable of achieving most of the requirements. .
- And much more!
- Read the Current Issue
Related Whitepapers
- Technology Brief: The Right Platform for Midsize Businesses to Provision IT Services
- How To Build a Mission-Critical Data Center
- Hardware vs. software deduplication: finding what's right for you
- Forrester TAP: Blades paper
- Virtualizing Tier 1 Applications: A Critical Step on the Journey Toward the Private Cloud
Featured Broadcast
In his book, The New Know: Innovation Powered by Analytics, Thornton May suggests that the key to business success is discovering truth and value from overwhelming amounts of data. This excerpt summarizes 10 fundamental realities for organizations moving forward.
Learn More













