Trojan exploits Android security fix

Powered by SC Magazine

Antivirus vendors find a mobile home.

Malware writers have repackaged Google’s recently released Android Market Security Tool with a bonus Trojan. 

The fake Android security tool exploits Google’s answer to the information-stealing DroidDream malware, which had up to 200,000 users.

Google’s real clean up tool promised to remotely wipe 50 offending applications from Android devices and remove the exploits to prevent attackers accessing further information.

The fake tool, meanwhile, allowed its controller to send SMS messages at will. Its impact is currently limited to Chinese Android users.

Symantec researchers discovered the fake Android security tool on a third-party Chinese marketplace.


Potential victims of the "Trojanised" clean up tool were advised to be on the look out for subtle differences between the real and fake security tool.

Vanja Svajcer, a virus researcher at Sophos, warned that the fake tool required additional permissions for "services that cost you money" as well as the device’s location.

Google’s tool was also labelled version 2.5 while the fake version was 1.5.

Fellow antivius firm, F-Secure, has posted visual comparisons of the fake and real tools here.

Sophos' Svajcer speculated that the fake clean up tool could spell the beginning of "scareware" for mobile phones -- a technique commonly used to lure Windows PC victims.

"Judging by the popularity of Android devices and the recent increase in malware attacks, it may be just a matter of time before we start seeing highly suspicious products like Antivirus Android 2012 on the market," he said.

Svajcer criticised Google’s decision to open its mobile applications market to unofficial trading platforms.

"Personally, I think that the ability to install non-market applications and ability to create third party application markets was a mistake for Google's Android team from the security point of view. This path is leading us to Windows-like threat levels."

Meanwhile, Tim Armstrong, a virus researcher with Russian antivirus outfit Kaspersky Labs, has criticised Google for releasing a tool which failed to fix the actual vulnerability.

"We’ve had a look at this app, and it does not fix the vulnerability, it simply removes the applications known to be malicious," Armstrong said on Monday.

Copyright © . All rights reserved.

Trojan exploits Android security fix
Top Stories
Myer CIO named retailer's new chief executive
Richard Umbers to lead data-driven retail strategy.
Empty terminals and mountains of data
Qantas CIO Luc Hennekens says no-one is safe from digital disruption.
BoQ takes $10m hit on Salesforce CRM
Regulatory hurdles end cloud pilot.
Sign up to receive iTnews email bulletins
Latest Comments
Who do you trust most to protect your private data?

   |   View results
Your bank
Your insurance company
A technology company (Google, Facebook et al)
Your telco, ISP or utility
A retailer (Coles, Woolworths et al)
A Federal Government agency (ATO, Centrelink etc)
An Australian law enforcement agency (AFP, ASIO et al)
A State Government agency (Health dept, etc)

Do you support the abolition of the Office of the Information Commissioner?

   |   View results
I support shutting down the OAIC.
I DON'T support shutting the OAIC.