30+ Infected Apps Pulled From Android Market
Trailrunner7 writes "Researchers have identified a second large batch of apps in the Android Market that have been infected with the DroidDream malware, estimating that upwards of 30,000 users have downloaded at least one of the more than 30 infected apps. Google has removed the apps from the market. There are at least 34 applications that researchers have found in the Android Market in the last few days that had a version of the DroidDream malware dropped into them. Once a user installs one of the infected applications, the malicious component, which researchers have dubbed DroidDream Light, will kick in once the user receives an incoming call. The malware then gathers some identifying information from the phone, including its IMEI number, IMSI number, packages installed and other data, and then sends it off to a pre-configured remote server."
Again, no list in TFA.
You have to dig through it to another article that links to a source article with a list:
http://blog.mylookout.com/2011/03/security-alert-malware-found-in-official-android-market-droiddream/
And that list is over two months old.
Which means this story's hardly viral. More like fungal.
The Lookout Blog has a list of the affected apps.
http://blog.mylookout.com/2011/05/security-alert-droiddreamlight-new-malware-from-the-developers-of-droiddream/
Can't wait for the day when such actions aren't news.
Here's the list: http://blog.mylookout.com/2011/03/security-alert-malware-found-in-official-android-market-droiddream/
They should open source it, it won't get any malware then.
Oh wait..
http://blog.mylookout.com/2011/03/security-alert-malware-found-in-official-android-market-droiddream/
http://blog.mylookout.com/2011/05/security-alert-droiddreamlight-new-malware-from-the-developers-of-droiddream/
I can't tell if this is trolling, or if there's someone on /. that actually thinks that leaving the house, exercise, and eating anything besides energy drinks and cheetoes is a good idea...
But it is summer, maybe I should go outsi--
oh look! COD has a new map pack!
Dr. Bob is the resident chiropractor quack at
He'll tell you at length about how all human suffering is caused by "subluxations". He appears to be a Luddite yet claims to have a techie streak in him.
If anything, his rants are most entertaining.
The only proper defense against nuclear cellphone radiation is a HOSTS FILE written by a LADYBOY CHIROPRACTOR!!
None of them can see the clouds; The polished wings don't care.
You can't tell if it's a troll?
Advertising to go to a chiropractor, in a discussion about cell phone apps, didn't give it away to you?
Hang on. Almost... GOT IT!
I wonder how many infected apps are in Apple's app store that /aren't/ getting removed? That's the beauty of the Android market!
Ah, but you see, cell phone RADIATION causes SUBLUXATIONS which then causes heart disease, cancer, cooties, AIDS, bad breath, gas and crossed eyes.
It's completely on topic!
Trolling is a art,
Only in Soviet Russia.
The issue deserves concern, but 30,000 Android users seems like a very small number to me.
I went to eat some animal crackers and the box said, "Do not eat if seal is broken." I opened the box and sure enough..
I use it about 5 minutes per month.
I commute by bicycle about 6 miles minimum each way to and from work. Sometimes 10 to 15, depending how I feel.
I get around everywhere by bicycle and walking
I eat raw vegan about 60 percent of the time; the rest is vegitarian.
I take no high fructose corn syrup. That stuff is poison.
If I am not out exercising, I am engaged in my hobbies of sewing, welding, glass engraving, and lapidary. I make stuff for the fun of it. If you want to see what I make, go to www.allyn.com for my art journal.
I have not had a couch or tv for about 30 something years.
Most Respectfully Yours Mark Allyn Bellingham, Washington
Radio waves were not 'invented'
Radio waves were discovered.
I know its off topic slightly but i got a call from a number ....or even text messages with a link to call this number...
on my iphone, i imagine they are making some malware for iphones too, or is that just wishful thinking on the part of parties involved calling me
to get me to click on a link...anyone know or have useful links on the iphone for this too???
greatly appreciated
Android is /free/, man!
Get your hand off it, dude. Public onanism is embarassing.
Good Afternoon mallyn,
This is Comcast posting to notify you the appointment we scheduled 30yrs ago to handle your TV outage is scheduled for sometime between 8:00 am EST tomorrow and 2020.
Will you be home at that time, or should we reschedule?
You may contact us at 1-8COMCASTIC or email us at lulz@comcastcares.not
Sig Follows: "Suppose you were an idiot. And suppose you were a member of Congress. But I repeat myself." -- Mark Twain
The apps were not "Infected" by the droid dream malware -- This would mean that malware was wandering around, infiltrating developer machines and the Marketplace itself... No. Instead, said malware payload was purposefully introduced to innocuous looking apps -- similar to the gift of a poison apple, or a Statuesque Wooden Horse Gift.
Hint: Legit app with "malware dropped into them." describes a malware infection about as well as Stigmata describes the actions of a depressed wrist slitter.
Apparently, the sex-censors have illegalized the word: Trojans. Either that, or the submitter is a moron.
Hmmm......walled garden, eh....(scratches chin thoughfully).....
You should really shop around then, they've made HUGE improvements in the last 30 years.
Sorry, but using logic to defend your favorite platform has no use here. Please move along.
Sincerely
An Apple Product User
The real Sig captains the Northwestern. This one captains
The malware only activates when you receive one of these "phone call" things - and when was the last time you received one of those?
Whatever it is, it's notablog.
Despise other comments to this post claiming that these apps had the malicious payload intentionally included, I can't find anything confirming that's the case. Are we sure it's not a matter for developer keys (or even the Google Marketplace or phone OS) getting compromised? Anyone see that info anywhere
What I don't get is why no-one writes the package names of the malicious apps.
Application names are generally useless on Android since they can be duplicated freely (and there are legit apps with those names).
On the other hand, package names are unique in the Market.
Anyway, the list of the apps with the package names from the **previous** outbreak can be found here: http://globalthreatcenter.com/?p=2091
Also, a question: does the kill switch affect devices which don't have the market installed?
and then sends it off to a pre-configured remote server
So is the physical location of this server know? Because if it is, then whopass and wedgies may be delivered directly.
The three laws of thermodynamics:(1) You can't win. (2) You can't break even. (3) You can't even quit.
The apps were not "Infected" by the droid dream malware -- This would mean that malware was wandering around, infiltrating developer machines and the Marketplace itself... No. Instead, said malware payload was purposefully introduced to innocuous looking apps...
Sorry, but using logic to defend your favorite platform has no use here. Please move along.
Actually, I think it's just as bad (if not worse) that these apps can go into the official android market with such little oversight that they contain blatant malware. I wonder how much other malware and spyware is out there in the market apps.
Most Android users have encountered apps in the market that provide some stupid little function, but want a wide array of unrelated permissions on the phone. Who is watching these things to see what they really do? And how many average users are really thinking critically about what the app is asking for? Security-wise, I am getting some serious Windows 95/98/NT deja vu from the the Android platform.
Without having to resort to reviewing third party code like Apple does, I see one possible way in which Google could solve this problem without dedicating too many people to it. My solution is this:
By default, a developer account on the Market is "unverified" - when people try to install apps from an unverified account, they receive a huge, scary warning that states that this application could contain malware, please make sure you trust the author, etc.
To become "verified", a developer must contact Google personally and verify their identity, including full contact details (phone number, address, etc.), and sign a form that states something to the effect of "You are liable for all malicious code published through this account, even if your account is hacked." Punishment for publishing malware could include a financial penalty, and possibly criminal charges depending on what your malware did and what jurisdiction you live in.
And yet any time there is any sort of major problem with android or the android market the issue is swept under the rug by a lot of android users on /. and the focus goes back to bashing people who use apple products or concentrating on problems with definitions or semantics in the article instead of the issue at hand. Yes, us Apple product users are the ones being illogical...
Why waste your time with the market, go after the owner of the server.
Sorry, teleporters just kill you and then make a copy. A perfect, soul-less copy.
Just install that, and anything that attempts to go to the net, request IMEI numbers or anything else, it pops up and asks permission. It's funny/scary to watch how many programs that have absolutely nothing to do with anything, request to send contact info, gps info, tower info and IMEI info.
Typical dumbs ass Apple User reply.
"The apps were not "Infected" by the droid dream malware -- This would mean that malware was wandering around, infiltrating developer machines and the Marketplace itself... No. Instead, said malware payload was purposefully introduced to innocuous looking apps..." is a totally correct statement for any platform.