Showing posts with label Malicious Apps. Show all posts
Showing posts with label Malicious Apps. Show all posts

Tuesday, 19 April 2016

Google: Sharp Drop In Android Malware On Google Play


The number of malicious apps in Google Play has dropped sharply last year, says Google in a new report. For the second time the Internet giant published the Android Security annual report ( pdf ). Compared to 2014 took the risk of the installation of malicious applications by 40% in 2015.

The malicious apps are divided by Google in various categories like apps that collect data, spyware, Trojans and apps to download additional software. The percentage of apps which collects data decreased by 40%, to 0.08% of all installations.Spyware decreased by 60% to 0.02% of the installations and malicious downloaders saw a 50% decrease to 0.01% of all installations. However, the category of Trojans rose from 0.01% to 0.02%. Eventually it was less than 0.15% of all Android Devices that download malicious apps from Google Play only apps installed.

About 0.5% of the devices that was downloaded from Google Play apps as well as other resources to deal with malicious apps. In addition, Google says that it also protects users download these apps from other sources. For this, use the Verify Apps. Warnings Verify apps were improved last year, which was an increase of 50% of users decided not to install the app in question after a warning. End of 2014 Android Phones got to it first with ransomware. This category of malware was according to Google last year found only outside of Google Play.

Thursday, 8 October 2015

Kemoge Adware: Aggressive Android Adware Trying To Rooten Devices


There is a new instance of aggressive Android adware discovered spreading via unofficial app stores and tries to Android devices through various vulnerabilities to 'rooting'. Although for years advised by experts and security to only download apps from official app stores, there are still users who use so-called "third party" app stores.

The now discovered Kemoge-adware poses as many different apps. The makers have taken the original apps and features the adware. Then placed the packaged apps in the unofficial app stores. Once active adware makes use of eight different exploits to get onto the phone via known vulnerabilities root privileges. The app collects all kinds of information from the device and lets see ads everywhere, even on the Android home screen. The name given to the malicious Adware family is because of its command and control (C2) domain:aps.kemoge.net.


Then the adware makes contact with a command-and-control server and wait for further instructions. The server can install any apps on the infected device, uninstalling or starting. The adware is found worldwide, says security firm FireEye. To avoid infection, users advised never to click on suspicious links in emails, text messages or advertisements. No apps outside the official app store to install, and finally to keep the Android device up to date. This is to prevent malicious apps to the device via known vulnerabilities can rooting.

Wednesday, 7 October 2015

Dozens Of Fake Apps In Windows Phone Store Discovered


In the Windows Phone Store Microsoft researchers have discovered dozens of fake Apps posing as popular apps like Facebook Messenger, CNN, BBC and WhatsApp. Reported anti-virus company Avast. A total of 58 different apps from its two developers coming.

The purpose of the apps is to maximize revenue. The developers use two tactics, namely, ad-clicks and misleading advertisements. The apps include several ad kits, where both users and app itself is clicked. Misleading ads try to lure users to certain malicious Websites, for example, claim that the device is infected or has other problems. How many people have downloaded the apps is unknown. At the time of writing were still finding the apps in the Windows Phone Store.

Thursday, 10 September 2015

Malware On Google Play Subscribe Victims On SMS Service



Google Play researchers have discovered Android malware that tries to subscribe victims of costly SMS services. The malware was late last year noted for the first time, but was then distributed only through unofficial marketplace. Now the malware surfaced in Google Play.

Once the malware is actively attempting to subscribe users to costly SMS services. These services require that a CAPTCHA code solved. To this end the malware using Antigate.com, an online service where people CAPTCHA codes solve fee.The code is then dissolved the victim subscribed to the SMS service.

The malware was found to be hiding in different apps. Two of these apps were downloaded between 100,000 and 500,000 times, reports the Romanian antivirus company BitDefender. In total there are seven apps, of which several versions are always placed in Google Play. Google would now be informed of the malicious apps.

Sunday, 30 August 2015

Researchers Found 30 000 Infected Apps On Google Play


Researchers at Indiana University have developed a scanner that allows them to rapidly scan hundreds of thousands of Android apps, which ultimately resulted in 30 000 infected apps on the official Google Play store. MassVet (pdf) as the scanner is called, can determine within seconds whether an app is benign or malignant, without knowing how the malware looks or behaves.

Instead of analyzing the app MassVet compares it with apps that already exist in the relevant store. Most Android malware is in fact repackaged apps. When cybercriminals repacking apps add malicious components increasing. Therefore differs repackaged app of the original. The malicious components in applications can also be found who seem to have nothing to do with each other.

The researchers decided to test the scanner with 1.2 million apps from 33 different app markets. MassVet proved apps within 10 seconds, assess and outperformed 54 virus scanners on VirusTotal. Of the 1.2 million-controlled apps were found to be more than 127 000 malignant and 34 000 were missed by most malware scanners on VirusTotal. Some of the malware specimens were installed millions of times. It also found that 5000 malicious apps each had more than 10,000 installations.
Google Play

Also analyzed MassVet 400 000 apps on Google Play, of which 30 000 were found to be malignant. This equates to an infected rate of 7.6%. According to the researchers this different from earlier figures of Google. According to Google, was found on Android Users who only install apps from Google Play at less than 0.15% of the devices a "potentially malicious application" (PHA).

However, users of China's market places that are most likely to Android malware. In the market places of Anzhi, Yidong, yy138 and Anfen was 39%, 36%, 28% and 23% of all available apps malware. On the fifth of infected stores SlideMe comes back, 21% of the malware apps proved to be. The overview is also given to the store by Opera. This was 7.8% of the apps labeled as malicious.

Sunday, 26 July 2015

Fraudulent Mobile Ads Consume Gigabytes Of Data



Fraudulent apps for both Android, iOS and Windows Mobile posing as popular games allow devices actually charging thousands of ads a day, without users having this in the first instance. However, the applications run continuously in the background, may consume gigabytes of data, ensure that the battery previously absorbed and are able to download more than 16,000 ads per day.

Then there are simulated random clicks on the ads, which get the developers of the paid apps. Average would be the apps on a device 700 ads download per hour, which amounts to 16 800 ads per day. It consumes about 2GB of data. Globally, there are more than 12 million devices with rogue apps are infected.

According to the US Forensiq have rogue apps produced last year for $ 857 million in damages and this year will be $ 1 billion to be passed. It should be noted that Forensiq a company engaged in the fight of advertising and click fraud. Google has already removed several of the rogue apps from Google Play, but would not say how many, reports AdvertisingAge .

Friday, 10 July 2015

Apps On Google Play Trying To Steal Facebook Password


Two apps on Google Play, including a fairly popular game between 500,000 and 1,000,000 plants, tried to steal passwords of Facebook users. Of the apps here also succeeded unknown. That report anti-virus companies ESET and Trust Look .

The apps, Cowboy Adventure Jump and Chess were fitted with malicious functionality. Unlike other Android malware went here really working games. Once the apps were launched, however, there appeared a fraudulent log-in window for Facebook.When users intrapten here and filled in the details which were sent to the attackers. After being informed Google removed the apps from the marketplace.

Jump Chess, which was derived from the same developer, it was found with 1,000 to 5,000 plants much less popular. In addition to removing the Google also warns users try to install the apps. Although the opportunity for abuse was present, it is unknown whether the victims were taken. Many users left negative comments about Cowboy Adventure behind and warned that the application tried to steal login details.

Monday, 29 June 2015

VU Researchers Reveal Vulnerability In Android


Researchers at the Free University in Amsterdam have revealed a vulnerability in Android which an attacker can install using the stolen credentials to a Google Account in several steps malicious apps on devices.

The problem is caused by one Google account used for different devices. An attacker who successfully infect the computer of an Android user knows and manages to steal the password of the Google Account can then install apps on all Android devices associated with that account, so the researchers had this weekend at the Volkskrant know. The devices showed the researchers used only during the installation process notifications in the notification bar, as downloading and installing the app.

"But once this was done, there was nothing more to see until the notification screen is explicitly opened. It is also true that the icon of the app does not always end up on the main screen, but sometimes only at the 'all apps' list, for example, if your main screen already filled, or - if the app is published correctly -. We did not make use of the latter, "said university researcher Victor van der Veen . Together with researcher and professor Radhesh Krishnan system and network Herbert Bos discovered and he researched the issue.

Play Store

Van der Veen says that can be installed through the attack vector only apps from the Play Store. According to the researcher then has two options attacker. Or placing a simple app on Google Play, which will be opened after installing a new rogue app.These users, however, would have to set themselves apps from external sources can be installed. Something that is disabled by default. The second option is to install an app on Google Play containing all malicious code. "Meanwhile we have several 'bad' applications received in the Play Store without being detected as malicious by Google," Van der Veen.

Through the malicious app, an attacker can then perform a variety of actions on the device, such as the interception of text messages or turn on the camera. The researchers warned Google late last year, but the Internet giant would want to do anything about the problem. Van der Veen advises users who want to protect themselves against possible attacks to watch.So should be immediately removed unsolicited downloaded apps and the option "Install from external sources" are disabled.Also users should change their passwords regularly. "Especially when there are suspicious or strange signals. And protect your PC, because the criminals come for the first time," the researcher noted.

Saturday, 28 February 2015

Aggressive Android Adware discovered on Google Play


Researchers from the Romanian antivirus company Bitdefender have on Google Play different Android apps discovered containing aggressive adware. Using apps after installation on the device a different name, which may make it more difficult for users to find and remove them.

Once active show the apps, such as "What is my IP?", All kinds of so-called warnings to install subscribing users on expensive telephone or make additional apps that contain more ads. One possible reason that the apps Google checkout managed to avoid is that the URL that sends users does not point to malicious APK files. The URL allows browsers to open a website that users from one ad to another forward.


For example, users in each search, clicked URL or open Facebook link to a special page redirected showing various location-specific ads. "Aggressive adware has in recent years developed further in-app ads and adware software development kits, to browser redirects and turning legitimate apps under similar names," said analyst Liviu Arsene. Some of the apps are as Bitdefender still be found on Google Play.

Hashes:

f2d57300d5f991dbc965ac092d5f4301 – com.alm.alm
c1d7afa5c4eb0b8e3c0292eadf98771e – com.tr.dum.dum
16967bea7d3dcb08c12220925ef6f030 – com.est.hk
cb9d3ff0eea162dd602eefe7b08ded49 – com.est.esteban
dbc99ba3241f943cc9e58870f0e40b34 – com.brer.brer
51bc232de9af3f34a58d824da86a70bc – com.tr.ipp
996c4a1525729466d87edf85cbbdf5de – com.who.myip.detect
6f37bd3c286440e37103ee8b67aca7d6 – com.tf.fed
47b863625a8022399247fc92c4d5d178 – com.esc.escd
e1ccb51569635415e66af16cbdd94ddc – com.esc.escde