Slashdot Mirror


'Fee-Deduction' Malware On Android Spotted In the Wild

wiredmikey writes "New malware has been discovered embedded in more than 20 Android applications circulating via various forums on the Internet which auto-dials phone numbers to incur high user fees. Dubbed BaseBridge, the malware can be embedded in legitimate applications, and during the application's installation, the malware prompts the user to upgrade. If the user chooses to upgrade, the malware is installed on the Android device under the name 'com.android.battery'. Then, another prompt would pop up to ask the user to restart the app to run it, and the malware is formally activated upon restart. Once activated, the malware can activate three malicious services — AdSmsService, BridgeProvider and PhoneService, to communicate with a control server, from which it will download a configuration file to read related information and dial calls or send out SMS messages, incurring fees for users."

5 of 169 comments (clear)

  1. Um.. so which apps by bigredradio · · Score: 4, Insightful

    It would be nice to see a list of the Apps. If there are "over 20" the list is probably not too large to post.

  2. Re:Rather selfish by WhirlwindMonk · · Score: 5, Insightful

    If only there were a setting to allow sideloading. One that's disabled by default to protect unsavvy users, but is easily enabled by people who know what they're doing/willing to accept the risks. Oh, hey, look! There it is! "Unknown Sources: Allow installation of non-market applications."

    Good to know that the iphone has a similar setting, that was a good move on Apple's part. Oh, wait, it doesn't? You have to exploit security holes to enable sideloading? Huh. How about that.

  3. Re:What's the purpose of this? by TheRaven64 · · Score: 4, Insightful

    Not always. The best ones set up quite a low rate and don't make the malware call it more than once or twice. If someone gets a 50 charge on their telephone bill, then they are unlikely to query it. If they do, then the phone company will probably just give them a refund and eat the cost - they probably charge more than 50 for the call to their support line anyway. 50 doesn't sound like much, but if you get a couple of million infections then that's a huge amount of money. Ideally, they'll register a few hundred premium rate numbers and have the malware dial a random one.

    --
    I am TheRaven on Soylent News
  4. Re:Linux doesn't appear to be immune to malware by Goose+In+Orbit · · Score: 2, Insightful

    Feeding time...

    I take you you use a perfect OS then? Do tell us what it is...

  5. Re:Well by cHiphead · · Score: 4, Insightful

    In my day, we called that "installing" a program. Sideloading? Really? What has the world come to? DRM-ified nonsense.

    --

    This is my sig. There are many like it, but this one is mine.