Slashdot Mirror


New Android Malware Robs Bandwidth For Fake Searches

adeelarshad82 writes "We've been hearing about various Android malware spreading through the Chinese markets. Well, here's another one to look out for: meet ADRD (aka Trojan:Android/Adrd.A) which is expert in sucking your bandwidth. The malware downloads a list of search URLs and then performs those searches at random in the background, which as the screen shots [in the linked article] show leads to excessive data charges. Similar to other Android malware this too is distributed through wallpapers which are infected repackaged versions of legit wallpapers." Adds reader Trailrunner7: "Lookout, a mobile security vendor, said it has identified 14 instances of the malware repackaging itself in various wallpaper apps and specifically in the popular game RoboDefense, made available in alternative application markets. The trojan works by duping an infected app into sending encrypted data containing the device’s IMEI and IMSI to a remote host. HongTouTou then receives a set of search engine target URIs and search keywords to send as queries. It then uses these keywords to emulate search processes, creating searches in the search engine yielding the top results for those keywords and clicking on specific results. To the search engine, the searches appear to be coming from a mobile user using a mobile web browser with User-Agent corresponding to the UCWeb browser."

1 of 236 comments (clear)

  1. Re:We're Not Surprised by Divebus · · Score: -1, Flamebait

    Where's the OSS oversight for all the random "open" apps on Android? Doesn't exist, buddy. The "open" model just broke. People can write anything and release it with millions of suckers getting hosed instantly.

    It's "open" like your anus. Android - the electronic equivalent of being bent over in Times Square with your knickers down to your ankles. You call that success? The whole ecosystem of Google appears to be malware. All your datas belong to us! Now these hoseheads are showing up in droves.

    --

    Most of the stuff on /. won't survive first contact with facts.