Android DreamDroid two: rise of laced apps

Powered by SC Magazine
 

DreamDroid Light hits up to 130,000.

A smartphone security firm claims to have found 26 legitimate Android apps that had been laced with malware. 

The once-legitimate applications were modified to include what researchers from security firm Lookout called a “stripped down version” of DreamDroid, which it dubbed DreamDroid Light.   

The malware is activated by an incoming call, according to Lookout’s spokesperson, Tim Wyatt, which meant that users would not have to launch the application to trigger its behaviour.

Lookout has estimated the applications have been installed on 30,000 to 120,000 devices.  

Like its predecessor, the tainted application sends identifiers (IMEI/IMSI) to the malware's distributors, however DreamDroid Light would require user-interaction to steer its way through an update.   

Google has removed the program while it investigates the claim, according to Forbes security blogger, Andy Greenberg

Lookout discovered the malware after a developer had alerted it to a modified version of one of his apps, which was being distributed on Google's Android Market. 

“Our security team confirmed that there was malicious code grafted into these apps and identified markers associating this code with previously analysed DreamDroid samples,” wrote Wyatt. 

A list of the affected apps, which ranged from “hot girls” to systems monitoring tools, can be found on Lookout’s website.

One of the apps, Hot Girls 1, had the capacity to create a “mobile botnet”, according to F-Secure chief researcher, Mikko Hypponen. 

In that instance, receiving a text message will activate malicious components of the app. 

“The added code will connect to a server and send details about the infected handset to the malware authors. So we're talking about a mobile botnet,” he said

Copyright © iTnews.com.au . All rights reserved.


Android DreamDroid two: rise of laced apps
 
 
 
Top Stories
Westpac interim CIO resigns
Group CIO yet to be appointed.
 
Earning the right to innovate
Breaking down the barriers to innovation is a long, but rewarding process, says Bank of Queensland Group CIO, Julie Bale.
 
Telstra prepares to shut down 2G network
Update: Will farewell "old friend" by end of 2016.
 
 
Sign up to receive iTnews email bulletins
   FOLLOW US...
Latest articles on BIT Latest Articles from BIT
Pass on carbon tax savings, warns ACCC
Jul 24, 2014
The ACCC is warning businesses that supply "regulated goods" to pass on any cost savings ...
Have customers that won't pay debts?
Jul 10, 2014
The ACCC and ASIC have updated their advice when it comes to collecting debts.
Carpet cleaner faces court over online testimonials
Jul 4, 2014
The ACCC has initiated proceedings against A Whistle (1979) Pty Ltd, the franchisor of Electrodry...
You can now get 15GB of free online storage using Microsoft OneDrive
Jun 25, 2014
Cloud storage has reached both the capacity and price where it's a viable alternative to local ...
Another clever trick you can perform with Xero
Jun 25, 2014
Here is another way to reach out to particular subsets of your customers using Xero.
Latest Comments
Polls
What is delaying adoption of public cloud in your organisation?







   |   View results
Lock-in concerns
  26%
 
Application integration concerns
  3%
 
Security and compliance concerns
  28%
 
Unreliable network infrastructure
  9%
 
Data sovereignty concerns
  23%
 
Lack of stakeholder support
  3%
 
Protecting on-premise IT jobs
  5%
 
Difficulty transitioning CapEx budget into OpEx
  3%
TOTAL VOTES: 906

Vote