Jump to content


Photo

The Mechanics of Android Malware Revealed

Android Malware scams permissions

  • Please log in to reply
3 replies to this topic

#1 eyecre8

eyecre8

    Mod/News Team Leader

  • Moderator
  • 108 posts
  • Google+:eyecre8
  • LocationOhio/Florida
  • Current Device(s):2 Razr's (xt912) & Asus TF700T

Posted 03 July 2013 - 10:21 AM

The Mechanics of Android Malware Revealed

 

Please Login or Register to see this Hidden Content

 

Please Login or Register to see this Hidden Content

  54.83KB   18 downloads
 
Full Report with graphs/charts found here: 

Please Login or Register to see this Hidden Content

 
According to McAfee, criminals use the cover of free apps to dupe consumers into agreeing to "invasive permissions" that grant the malicious app access to personal information.
 
Some of this info can be used to serve up targeted ads, so-called 'adware', which makes up 74 percent of all the malicious apps McAfee discovered online.
Other apps access permissions to send pricey SMS messages or trick users into granting an app publisher a five star rating (thereby enabling it to rank higher in the app store and lure more unsuspecting users).
 
McAfee has found SMS malware that send 7 messages. At a premium rate of $4 USD per message, $28 USD is a high price to pay for a “free” app.
 
This, more exploitative malware, accounted for 26 percent of malicious apps McAfee discovered lurking in mobile Android apps stores. McAfee also found that some apps get permission to intercept outgoing calls, change UI settings or access core system settings. The most susceptible app categories for Android malware were games, followed by personalization apps, 
tools, music, lifestyle apps and TV apps.
 
Aggressive permissions endanger privacy and permit scams. Most mobile users do not understand mobile app permissions. Even more do not worry about them. Here is the problem: as consumers get less sensitive to permissions, they accept more permissions. Every extra permission provides an opportunity for criminals.
 
The permissions in “free” apps leak personal information, which ad networks use to target their ads: “Here’s a coupon for a store near your current general location.” 
However, we find that 26% of apps are more worrisome than just adware. They contain the most invasive ad networks, those that collect precise GPS location, account, and activity information. 
Many include malware that runs an SMS swindle or gives a criminal remote control of the device as a bot client. Aggressive permissions let these invasive ad networks and malicious attacks succeed.

RootSmart and DroidDream threats are the most sophisticated and invasive we have ever seen: 

they will send handset information as well as install a downloader that lets them add spyware, 
rooting malware, and backdoor or botnet software to your device. With all that extra software on board, 
you may have rooted your device, but it is the attacker that is really in control. 

 

For example, in April 2013, McAfee researchers dug into an attack that added data-stealing permissions to create a Trojanized version of the KakaoTalk instant messaging app. The attackers sent forged emails with an Android app as an attachment and used social engineering to convince victims to install the malicious app. The attackers added subtle but potent permissions that allowed them to install their malware and monitor messages and calls.

Please Login or Register to see this Hidden Content

 

Please Login or Register to see this Hidden Content

  56.99KB   19 downloads
 
 
The bottom line: be careful about what apps you download and always scrutinize the kinds of permissions an app is seeking before you download it, especially if it's a freebie in any of the above categories.
 
 
 
 
To read the complete article see:

Please Login or Register to see this Hidden Content

Please Login or Register to see this Hidden Content


 

 

 

Enlightening users one person at a time


  • neckchop, satman80 and jl90 like this
My name is Eyecre8 and I approve this message!
Posted Image

#2 jl90

jl90

    \m/

  • Developer
  • 1,642 posts
  • LocationPhoenix, Az.
  • Current Device(s):Nexus 6 64GB, RAZR HD Maxx

Posted 03 July 2013 - 10:28 AM

Really nice write up!! Should be required reading for new smartphone users. :)
  • satman80, livinginkaos and eyecre8 like this

#3 livinginkaos

livinginkaos

    I don't know what I'm doing anymore.....

  • Administrator
  • 15,282 posts
  • Google+:Hangouts - livinginkaos@gmail.com
  • LocationOregon
  • Current Device(s):Samsung S8+ / Pixel XL 128gb / iPhone 7+ 256gb / iPad Pro 12.9" / Samsung Chromrbook Plus / Pixel C / Nexus 6p 128gb / Nexus 6 / Nexus 6 on Fi / Nexus 9 / Moto 360^2 / Nvidia Shield TV Pro / Nvidia Shield Tablet / HTC EVODesign on FreedomPop / Chromecast / Surface Pro 3 i7 / Samsung Tab Pro 12.2 / Lenovo Win8 Tab / Eee Slate / '13 Nexus 7

Posted 03 July 2013 - 11:10 AM

Dude, you've done it again ...... NICE JOB !  I agree with jl90, this should be something that pops up on a new phone when you first turn it on.


  • satman80, eyecre8 and jl90 like this

b2wvCBn.png

Sig by livinginkaos
Samsung S8+ / Pixel XL 128gb / iPhone 7+ 256gb / iPad Pro 12.9" / Samsung Chromrbook Plus / Pixel C / Nexus 6p 128gb / Nexus 6 / Nexus 6 on Fi / Nexus 9 / Moto 360^2 / Nvidia Shield TV Pro / Nvidia Shield Tablet / HTC EVODesign on FreedomPop / Chromecast / Surface Pro 3 i7 / Samsung Tab Pro 12.2 / Lenovo Win8 Tab / Eee Slate / '13 Nexus 7


#4 eyecre8

eyecre8

    Mod/News Team Leader

  • Moderator
  • 108 posts
  • Google+:eyecre8
  • LocationOhio/Florida
  • Current Device(s):2 Razr's (xt912) & Asus TF700T

Posted 03 July 2013 - 11:35 AM

as good 'ole Ben Franklin said:  "“An ounce of prevention is worth a pound of cure.”

 

Imagine what a staggering hit malware infestations would take if this were taught to users.


  • jl90 likes this
My name is Eyecre8 and I approve this message!
Posted Image





Also tagged with one or more of these keywords: Android Malware, scams, permissions

1 user(s) are reading this topic

0 members, 1 guests, 0 anonymous users