Breaking News

CORSAIR Launches ThermalProtect PCIe 5.1 600W 12V-2x6 Cable to Help Protect GPUs from Overheating Logitech announces G512 X Gaming Keyboard ASUS Announces TUF Gaming Platinum Power Supply Series TerraMaster announces D1 SSD Rugged Enclosure COLORFUL Introduces New BATTLE-AX B860M and B760M Motherboards with Wi-Fi 7 and Next-Gen CPU Support

logo

  • Share Us
    • Facebook
    • Twitter
  • Home
  • Home
  • News
  • Reviews
  • Essays
  • Forum
  • Legacy
  • About
    • Submit News

    • Contact Us
    • Privacy

    • Promotion
    • Advertise

    • RSS Feed
    • Site Map

Search form

Preinstalled Malware May Be Targeting Your Android Phone

Preinstalled Malware May Be Targeting Your Android Phone

Smartphones Mar 11,2017 0

Security firm Check Point has recently detected a severe infection in 38 Android devices, belonging to a large telecommunications company and a multinational technology company. Interestingly, the malware was pre-installed.

According to the findings, the malware were already present on the devices even before the users received them. The malicious apps were not part of the official ROM supplied by the vendor, and were added somewhere along the supply chain. Six of the malware instances were added by a malicious actor to the device's ROM using system privileges, meaning they couldn't be removed by the user and the device had to be re-flashed, Check Point said.

Most of the malware found to be pre-installed on the devices were info-stealers and rough ad networks, and one of them was Slocker, a mobile ransomware. Slocker uses the AES encryption algorithm to encrypt all files on the device and demand ransom in return for their decryption key. Slocker uses Tor for its C&C communications.

Among the "pre-infected" smarphones are the following:

  • LG G4
  • Galaxy S4
  • Galaxy S7
  • Galaxy Note 2
  • Galaxy Note 3
  • Galaxy Note 4
  • Galaxy Note 8
  • Galaxy Note 2
  • Galaxy Note Edge
  • Galaxy A5
  • Galaxy Tab S2
  • Galaxy Tab 2
  • Xiaomi Mi 4i
  • Xiaomi Redmi
  • ZTE x500
  • Nexus 5
  • Nexus 5X
  • Oppo N3
  • OppoR7 plus
  • vivo X6 plus
  • Asus Zenfone 2
  • LenovoS90
  • Lenovo A850

The most notable rough adnet which targeted the devices is the Loki Malware. This complex malware operates by using several different components; each has its own functionality and role in achieving the malware's malicious goal. The malware displays illegitimate advertisements to generate revenue. As part of its operation, the malware steals data about the device and installs itself to system, allowing it to take full control of the device and achieve persistency.

As a general rule, users should avoid risky websites and download apps only from official and trusted app stores. However, following these guidelines is not enough to ensure their security. Pre-installed malware compromise the security even of the most careful users. In addition, a user who receives a device already containing malware will not be able to notice any change in the device's activity which often occur once a malware is installed.

The discovery of the pre-installed malware raises alarming issues regarding mobile security. Users could receive devices which contain backdoors or are rooted without their knowledge.

Tags: Android malware
Previous Post
Samsung Starts Teasing With Galaxy S8 TV Ad As LG G6 's Sales Take Off
Next Post
Intel Security releases EFI rootkit checker Following WikiLeaks Reports

Related Posts

  • Google Play Store is Just Not Completely Safe Yet

  • Google Play Protect Removed Almost 2 Billion Malware Apps in 2019

  • US Government-funded Phones Come Pre-installed with Unremovable Malware: Malwarebytes

  • Google Launches the App Defense Alliance to Fight Bad Apps

  • Android Dropper App Infects 45K Devices in Past 6 months

  • Millions Android Phones Infected With 'WhatsApp' Malware

  • Researchers Discover 2,000 Fake Apps on Google Play

  • Most Antimalware Security Apps Don't Detect All Android Threads

Latest News

CORSAIR Launches ThermalProtect PCIe 5.1 600W 12V-2x6 Cable to Help Protect GPUs from Overheating
Enterprise & IT

CORSAIR Launches ThermalProtect PCIe 5.1 600W 12V-2x6 Cable to Help Protect GPUs from Overheating

Logitech announces G512 X Gaming Keyboard
Gaming

Logitech announces G512 X Gaming Keyboard

ASUS Announces TUF Gaming Platinum Power Supply Series
PC components

ASUS Announces TUF Gaming Platinum Power Supply Series

TerraMaster announces D1 SSD Rugged Enclosure
Enterprise & IT

TerraMaster announces D1 SSD Rugged Enclosure

COLORFUL Introduces New BATTLE-AX B860M and B760M Motherboards with Wi-Fi 7 and Next-Gen CPU Support
PC components

COLORFUL Introduces New BATTLE-AX B860M and B760M Motherboards with Wi-Fi 7 and Next-Gen CPU Support

Popular Reviews

Akaso 360 Action camera

Akaso 360 Action camera

Dragon Touch Digital Calendar

Dragon Touch Digital Calendar

be quiet! Pure Loop 3 280mm

be quiet! Pure Loop 3 280mm

Noctua NF-A12x25 G2 fans

Noctua NF-A12x25 G2 fans

Arctic Liquid Freezer III 360 Pro Argb

Arctic Liquid Freezer III 360 Pro Argb

Soft2bet and the unseen hardware that makes instant play possible

Soft2bet and the unseen hardware that makes instant play possible

Crucial T710 2TB NVME SSD

Crucial T710 2TB NVME SSD

JSAUX 65Wh Rog Ally Battery

JSAUX 65Wh Rog Ally Battery

Main menu

  • Home
  • News
  • Reviews
  • Essays
  • Forum
  • Legacy
  • About
    • Submit News

    • Contact Us
    • Privacy

    • Promotion
    • Advertise

    • RSS Feed
    • Site Map
  • About
  • Privacy
  • Contact Us
  • Promotional Opportunities @ CdrInfo.com
  • Advertise on out site
  • Submit your News to our site
  • RSS Feed