Showing posts with label Android Devices. Show all posts
Showing posts with label Android Devices. Show all posts

Monday, 12 March 2018

Android Manufacturer: Included Malware Is False Alarm



The Chinese manufacturer of Android devices Leagoo has removed to anti-virus company Doctor Web, which claimed that the manufacturer supplied devices with malware. The virus fighter claimed that it had found the Triada Trojan in the firmware of more than 40 models , including that of Leagoo.

The malware, which can download and execute additional malware and apps, without users knowing this, turned out to be present in a custom Android system library. This system library is used by all Android apps, which means that the malicious code is present in the memory of all running apps. According to Doctor Web, the malware was added at the request of a Leagoo partner and the manufacturer made this request.

Leagoo says in a statement that it is a false alarm. "The problem with the" virus warning "on Leagoo phones is mainly caused by differences in the virus detection of Chinese and foreign anti-virus software", according to the manufacturer. Leagoo states that all phones are scanned for malware by "top Chinese anti-virus software" to ensure that all devices are virus-free. In the future, Leagoo will also use "foreign algorithms" during scanning to prevent new virus warnings.

Tuesday, 19 April 2016

Android Device With Fingerprint Reader Often Locked


Android devices that have a fingerprint reader are more locked than devices that do not offer this option. This was reported in the published today Google Android Security annual report ( pdf ). The use of screen lock helps according to Google both privacy and security.

However, research shows that many users set a screen lock because they find it difficult. With the launch of Android 5.0, users can, however, choose the "Smart Lock" option, in which a device remains unlocked until it is held by the user. This can be determined on the basis of various items such as Bluetooth, on-body detection 'and a trusted location. This reduces the number of times a user must manually unlock his device.

Since Android 6.0 fingerprint readers are supported, however, and this has a positive effect on the use of screen lock. Users can now unlock your phone using just their fingerprint. From Google figures show that the use of screen lock is more common on devices with a fingerprint reader. Is set at 55.8% of the Nexus 5 and Nexus 6 devices screen lock. With Nexus and Nexus 5X- 6P devices, which have a fingerprint reader, this is 91.5%. With other Android devices that have screen lock is being used on a fingerprint reader.

Thursday, 5 November 2015

Free App Scans Android Devices For Vulnerabilities


An American company has developed a free open source app that scans Android devices for vulnerabilities. According NowSecure it often happens that manufacturers do sometimes months to close serious security holes like Stage Fright in their version of Android.

Vulnerabilities can be present in many parts of Android. In the case of vulnerabilities in the kernel, according NowSecure difficult to control this without causing system instability. Something in the Android Vulnerability Test Suite account is held with. The app scans on several major vulnerabilities. All data while keeping within the device and be shared with anyone.Also, the source code of the app via Google Play is available for download at GitHub to see.

Wednesday, 4 November 2015

Google Hacks Samsung Galaxy S6 During Internal Competition


During an internal competition at the offices of Google are employees of the Internet giant has managed to hack a Samsung Galaxy S6 Edge, which ultimately resulted in 11 serious vulnerabilities. Google has a team of hackers called Project Zero.

The team looks for vulnerabilities in popular software. This time, the hackers also decided to look at a handset from Samsung. Most Android devices are namely not created by Google, but by external parties, known as Original Equipment Manufacturers (OEMs). These manufacturers use the Android Open Source Project (AOSP) as the basis for their devices.According to Google, OEMs are an important area for Android screening.

Namely manufacturers add all kinds of code and applications increasing, which can introduce new vulnerabilities. The manufacturers decide if and when they deploy updates. After previously having been created by a Google Nexus device examined Project Zero now decided to look at the safety of an OEM device. In addition to finding vulnerabilities, the researchers were also curious to see how quickly they were resolved. It was ultimately for the Samsung Galaxy S6 Edge chosen because a high-end device with many users.

Competition

It was then decided to organize a match between the North American members of Project Zero and the European section. The teams were given a week's time for the challenge. Eventually there were 11 vulnerabilities discovered and reported to Samsung. Eight of the leaks were patched by Samsung during patch cycle of October. The remaining three will be resolved this month. Who the match between the two teams eventually won, Google has not disclosed.

Saturday, 10 October 2015

87% Android Devices Unsafe By Lax Manufacturers


Almost all Android devices that have been in circulation for the past four years to deal with vulnerabilities that they were vulnerable to malicious apps. And the fault lies with the manufacturers of the device does not generate timely security updates, say researchers (pdf).


Researchers at Cambridge University found that on average 87% of Android devices were unsafe in the past four years, because there is no security updates were available. However, some manufacturers are doing better than others. It appears that the Nexus devices from Google itself the best score, followed by LG and Motorola. Nevertheless score these devices insufficient.

The researchers created a formula where we looked at the number of devices with no known critical vulnerabilities, the number of aircraft used the latest version and the number of vulnerabilities that the manufacturer had resolved in no single device. In total there were to get 10 points. Google ends at the top with a 5.2. Samsung (2.7), Sony (2.5), HTC (2.5) and Asus (2.4) set of well-known brands, the lowest score down, according to the survey by Androidvulnerabilities.org.

According to the researchers, the lack of updates to Android devices is a well known problem. Recently, both Google and Samsung announced to release monthly security updates. By the performance of each manufacturer to publish the researchers want to make the issue visible and thus help consumers if they want to choose a device. This then encourages the manufacturers again to provide timely updates.

Furthermore, the researchers argue that Google has done well by addressing many of the risks. Users also are advised to only download apps from Google Play, as the apps are controlled there. "However, Google can not do everything, and recent Android security problems have made ​​it clear that this is not sufficient to protect users. Devices require updates from manufacturers, and most devices that do not get," says researcher Alastair Beresford.

Thursday, 8 October 2015

Kemoge Adware: Aggressive Android Adware Trying To Rooten Devices


There is a new instance of aggressive Android adware discovered spreading via unofficial app stores and tries to Android devices through various vulnerabilities to 'rooting'. Although for years advised by experts and security to only download apps from official app stores, there are still users who use so-called "third party" app stores.

The now discovered Kemoge-adware poses as many different apps. The makers have taken the original apps and features the adware. Then placed the packaged apps in the unofficial app stores. Once active adware makes use of eight different exploits to get onto the phone via known vulnerabilities root privileges. The app collects all kinds of information from the device and lets see ads everywhere, even on the Android home screen. The name given to the malicious Adware family is because of its command and control (C2) domain:aps.kemoge.net.


Then the adware makes contact with a command-and-control server and wait for further instructions. The server can install any apps on the infected device, uninstalling or starting. The adware is found worldwide, says security firm FireEye. To avoid infection, users advised never to click on suspicious links in emails, text messages or advertisements. No apps outside the official app store to install, and finally to keep the Android device up to date. This is to prevent malicious apps to the device via known vulnerabilities can rooting.

Wednesday, 30 September 2015

Russian Manufacturer Delivers Android Tablet With Malware


Every now and then discover investigators Android devices come standard with malware. In most cases, these changes to the operating system that have been implemented by the parties. The Russian anti-virus company Doctor Web reported now to have discovered a Russian manufacturer that an Android tablet from the factory provides all of malware.

It is Oysters, which is primarily active in the Russian market. The T104 HVI 3G tablet from the company's researchers at Doctor Web a Trojan horse. The malware can send all kinds of information about the device to its creators, as well as install all kinds of additional applications. In addition, the malware can turn on the option to install applications from untrusted sources. The Russian manufacturer has been informed about the problem, but the firmware that offers it's own website still contains the malware.

Monday, 14 September 2015

Google Takes Action Against Android Ransomware


With the latest version of the Android operating system that should appear, Google has taken measures against ransomware for late September. Late last year, the first copies of Android ransomware and since then there have appeared many variations. So this week became the first Android ransomware discovered devices with a locking pin.

With Marshmallow, such as Android version 6.0 is mentioned, Google has several measures for ransomware-makers will make a lot more difficult, according to security firm Symantec. Marshmallow will, in fact of a new permission model will use, in which users permissions should allow the moment of use. In this case, users will see a notification when an app wants permission from a "dangerous" category and then have to manually go to the settings of the app to enable this access.

Many Android ransomware using a specific permission to show some kind of warning system. This permission has been placed in the dangerous category. Symantec states that Marshmallow not automatically mean the end of ransomware, as the new permissions model is only valid if it is specifically on the Marshmallow software development kit (SDK) dir. If the ransomware an SDK from a previous Android version uses the ransomware can still work. Nevertheless expects the security that the new Android version will be an obstacle to ransomware makers.

Thursday, 27 August 2015

Trainee Security Company FireEye Developed Malware


A trainee of the American security company FireEye has developed malware that cyber criminals Android phones infected and could control completely. It is a 20-year-old American who was arrested in July as part of an operation against the Darkode forum.

This was a great forum for cyber criminals. The American was active in this forum and sold here, along with a Dutch accomplice, his Dendroid malware. Facing a US judge the man known to be guilty and made his apologies to the victims of his malware. He also said that he would use his skills in the future to protect computer users. FireEye security company had already announced in July that the trainee was sued by the authorities.

The Dendroid malware was offered at a cost of $ 300. Once active on a machine could steal the malware files and text messages, take pictures, surf the history readout and record conversations without casualties this had passed. The American was in his own words over a year working on the development of the malware. If convicted, the men could be imprisoned up to 10 years and a fine of $ 250,000, so inform the AP and the Pittsburgh Post-Gazette. The judge will rule on December 2.

Saturday, 1 August 2015

Seriously Android Leak Also To Attack On Apps And Websites


This week it was announced that there was a very serious leak is present in Android which allows an attacker installed on millions of Android phones malware by only sending a single MMS message. Stage Fright, such as the vulnerability is known, however, is also to attack in other ways, according to the Japanese anti-virus company Trend Micro .

Security Zimperium Stage Fright made known this week. Trend Micro says that it has also found the same vulnerability independently of Zimperium and on May 19 of this year has been reported to Google. This implies that at least two parties have discovered a critical vulnerability of this magnitude and this then Google decided to report.

Attack Vectors

Trend Micro, however, that there are more ways to use Stage Fright. In addition to sending an MMS message, an attacker can use an app to attack the vulnerability, and the use of a website. The vulnerability is caused by the way the Android media server handles MP4 files. This allows an attacker to cause a heap overflow and then execute arbitrary code such as installing malware.



In addition to sending a malicious MP4 file from an MMS message, it is also possible to embed such a file in a Web site or by allowing an app to open, and thereby infect an Android phone with malware. Google has already rolled out an update, but many Android users for patches depend on their telecom provider or manufacturer of the device if the device is still supported.According to Trend Micro, the problem in Android version 4.0.1 to 5.1.1, which represents 94% of all Android devices.

Monday, 27 July 2015

Millions Of Android Phones Vulnerable By New Leak



Researchers have discovered a serious vulnerability in Android which makes it possible to gain access to devices simply by sending an MMS message. Then an attacker can steal information, read emails, activate the microphone and perform other tasks. The vulnerability is in Stage Fright, a media library that handles various popular media formats.

Security Zimperium discovered vulnerability in the Android part, that the self worst Android leak calls so far. An attacker only needs namely to send an MMS message to execute code on the device. It is thereby even possible to remove the message before the user gets to see it. Only the acknowledgement is all that is visible. The researchers warn that the vulnerability is very serious, because there is no interaction from the victim is required.

Estimates suggest that 950 million Android devices running risk. The problem is particularly acute among Android versions Jelly Bean, which is about 11% of all Android devices. Zimperium warned Google that has already rolled out patches for Android. In many cases, telecoms providers and manufacturers are, however, responsible for distributing updates to their users and the security company also fears that it may take a long time before everyone is protected.

Two manufacturers, however, are a positive exception. Meanwhile the Black Phone Silent Circle is patched and Mozilla Firefox is protected from the issue. At the upcoming Black Hat conference in Las Vegas will have more details about the vulnerability are announced.

Thursday, 23 July 2015

Dozens Of Apps On Google Play Quietly Visit Porn Sites



Researchers have discovered in recent months, dozens of apps on Google Play that Android devices unnoticed kinds of porn sites allow visits. It involves a total of 60 apps posing as popular games, such Dubmash, Clash of Clans and Subway Surfers.

The apps are in the last period downloaded at least 210,000 times. Once active try the apps to hide from the user and then visit various porn sites in the background. Presumably the author get paid for the clicks generated by the apps. Clicks that advertisers think they are performed by people. According to anti-virus company ESET, there is a cat-and-mouse game between Google and the authors of the fraudulent apps. Once Google remove an app is a new upload.

Most of the fraudulent apps have no or a few tens of downloads before they are found and removed. A single app falls on, like Subway Surfers 2, which was downloaded at least 50,000 times. According to ESET caused the click fraud apps no direct harm to users, such as steal passwords, but they generate a lot of traffic that users with data limit on cost can hunt.

Friday, 17 July 2015

Trainee Security Company FireEye Suspected Of Cyber Crime


A trainee of the American security company FireEye is suspected by the US government to develop and distribute Android malware. The 20-year-old man Dendroid the malware could have developed. With this malware, it is possible to infect Android devices and to control remotely. According to the indictment , the trainee would Dendroid-malware offered by the Darkode Forum, yesterday by the FBI offline was extracted.

The man is studying at Carnegie Mellon University in Pittsburgh and was twice an intern at FireEye. There he was engaged in researching Android malware. In a statement to CNN FireEye confirms that the trainee is indeed indicted by US authorities and that his training has been discontinued for the time being. There is now an investigation into the activities of the man's place. According to CNN, there are concerns that the intern has compromised software FireEye and has the knowledge and tools of the company used to commit cyber crime.

Anti-virus firms Symantec and Trend Micro warned in the past for the Dendroid malware, which attackers full access to can get an Android device. Then data from the device can be stolen and it is possible to listen in on calls and take pictures.Dendroid was for a sum of $ 300 on forums offered for cyber criminals.

Saturday, 4 July 2015

Virus For Android Smart TVs Launched



An increasing number of television sets to have "intelligent" capabilities, which often means that they are connected via a mini-computer with the internet. There are several operating systems to drive the smart televisions, including Android TV Google.

The Russian anti-virus company Doctor Web already had a virus for Android smartphones, but now has a product specifically for smart televisions, media players and consoles launched that run on the operating system. "With the advent of the Internet of Things (IoT) era are not only computers and smartphones that run the risk of becoming infected, so they need anti-virus protection," said the virus fighter.

It would be particularly Android devices that are connected to the Internet and allow users to install software from unofficial marketplaces or USB drives that run according to Doctor Web risk. In case the Android TV device supports a remote control, the remote control can also be used to control the virus.

Monday, 29 June 2015

VU Researchers Reveal Vulnerability In Android


Researchers at the Free University in Amsterdam have revealed a vulnerability in Android which an attacker can install using the stolen credentials to a Google Account in several steps malicious apps on devices.

The problem is caused by one Google account used for different devices. An attacker who successfully infect the computer of an Android user knows and manages to steal the password of the Google Account can then install apps on all Android devices associated with that account, so the researchers had this weekend at the Volkskrant know. The devices showed the researchers used only during the installation process notifications in the notification bar, as downloading and installing the app.

"But once this was done, there was nothing more to see until the notification screen is explicitly opened. It is also true that the icon of the app does not always end up on the main screen, but sometimes only at the 'all apps' list, for example, if your main screen already filled, or - if the app is published correctly -. We did not make use of the latter, "said university researcher Victor van der Veen . Together with researcher and professor Radhesh Krishnan system and network Herbert Bos discovered and he researched the issue.

Play Store

Van der Veen says that can be installed through the attack vector only apps from the Play Store. According to the researcher then has two options attacker. Or placing a simple app on Google Play, which will be opened after installing a new rogue app.These users, however, would have to set themselves apps from external sources can be installed. Something that is disabled by default. The second option is to install an app on Google Play containing all malicious code. "Meanwhile we have several 'bad' applications received in the Play Store without being detected as malicious by Google," Van der Veen.

Through the malicious app, an attacker can then perform a variety of actions on the device, such as the interception of text messages or turn on the camera. The researchers warned Google late last year, but the Internet giant would want to do anything about the problem. Van der Veen advises users who want to protect themselves against possible attacks to watch.So should be immediately removed unsolicited downloaded apps and the option "Install from external sources" are disabled.Also users should change their passwords regularly. "Especially when there are suspicious or strange signals. And protect your PC, because the criminals come for the first time," the researcher noted.