New Attack Uses Attackers' Own Ad Network To Deliver Android Malware
Trailrunner7 writes "The concept of malware riding shotgun with legitimate mobile apps is not a new one. There have been a slew of cases in which attackers have compromised apps in the Google Play store and inserted malware into the file. But a new attack uncovered by Palo Alto Networks is using a new technique that starts with the user installing an app on her Android phone. The app could be a legitimate one or a malicious one, but it will include some code that, once the app is installed, will reach out to an ad network. Many apps include such code for legitimate ad revenue purposes, but these apps are connecting to a malicious ad network. Once the connection is made, the app will then wait until the user is trying to install another app and will pop up an extra dialog box asking for permission to install some extra code. That code is where the bad things lie. The malicious code immediately gains control of the phone's SMS app for both command and control and in order to sign the victim up for some premium-rate SMS services. The attack is interesting, said Wade Williamson, a senior security analyst at Palo Alto, because the attackers can use a legitimate ad network that's already connected to a group of apps and then at any given time flip the switch and begin using it for malicious purposes."
The app could be a legitimate one or a malicious one, but it will include some code that, once the app is installed, will reach out to an ad network. Many apps include such code for legitimate ad revenue purposes, but these apps are connecting to a malicious ad network.
Inotherwords "but it has malware in it for the ad portion that goes to a malicious ad network" - or the app IS malicious and not legitimate. An app isn't magically legitimate if only some portions of it are malware.
StarTrekPhase2 - The Five Year Mission Continues!
The only unix-based platform riddled with security issues, viruses and trojans problems.
PBKAC, as usual...
Yet another good reason to avoid ads, and ignore those you can't avoid.
Down With Slashdot BETA!!! I've been around the corner and seen the oliphant; you can only abuse me from your perspecti
Advertising on the internet is the most common route for malware by far. That's why I install ad blocking software everywhere. Marketers whine and complain about lost revenue and try to guilt you by saying they need that revenue to run the sites "for free"... but the truth is the way most advertising networks operate allow for "dancing, singing" ads -- that is, injectable javascript. Everything in the marketer's world these days is about using java to track, probe, manipulate, etc., web pages, with pop-overs, pop-unders, drive-bys, side to side scrollers, sound, motion, and anything else to get your attention.
None of this would be a problem if they stuck to fixed-size IMG tags and graphics. In other words... marketing is a virus. It's the plague. It's not the browser's fault... it's these asshole profiteers who try to be endlessly creative in force-feeding people crap they don't want.
#fuckbeta #iamslashdot #dicemustdie
Marketing is a disease, a cancer of the Web, it is a plague, and blocking software is the cure.
Get free satoshi (Bitcoin) and Dogecoins
> the app will then wait until the user is trying to install another app and will pop up an extra dialog box asking for permission
A couple of weeks ago when I described this attack, some commenters said it was impossible - an app can't wait until the user was expecting a permission prompt from a different app, then request more permissions itself, they said.
I wonder if they still think it's impossible now that it's publicly reported to be in the wild.
Shouldn't the article be more gender neutral. "...with the user installing an app on the Android phone". Please correct me if I'm wrong. English is not my native language.
spam on spam, or malware inside malware.
So Android apps aren't in a sandbox? Why does an app get a notification that another app is being installed AT ALL?
I avoid ads totally (especially malscripted ones) via hosts files:
---
APK Hosts File Engine 9.0++ 32/64-bit:
http://start64.com/index.php?option=com_content&view=article&id=5851:apk-hosts-file-engine-64bit-version&catid=26:64bit-security-software&Itemid=74
---
Yes, even on an android smartphone
(Via ADB/Android Debugging Bridge & its PULL command, but use smaller optimized hosts there folks - not much room, shitty caching (sorry google, it's true)).
As long as attacks = host-domain name based (most are, like 99%, especially via "immortal" fastflux + dynDNS malware the majority/prevalent type out there vs. IP addressed ones).
Hosts files do more with less in a single file & at a faster privelege level (ring 0/rpl0/kernelmode) than redundant crippled by default browser addons (that slow up already slower ring 3/rpl 3/usermode browsers & are advertiser owned (Ghostery/Adblock "foxes guarding your henhouse")).
"Less is more" = GOOD engineering via less complexity, room for breakdown, & less "moving parts"/variables in the equation.
"The premise is, quite simple: Take something designed by nature & reprogram it to work FOR the body, rather than against it..." - Dr. Alice Krippen "I AM LEGEND"
Since "They're not gonna stop..." - Dr. Robert Neville "I AM LEGEND" @ that film's near termination...
APK
P.S.=> Hosts work by acting as a filter for the IP stack itself (written in C language & starts with the OS + 1st request to the internet it is the 1st resolver queried as well, with over 45++ yrs.of optimization refinement put into it).
Hosts also aid reliability vs. downed DNS & protect vs redirected DNS servers also securing you vs. known bad hosts-domains online http://tech.slashdot.org/comments.pl?sid=3985079&cid=44310431 & . Hosts files give users of them good benefits in added speed, security, reliability & even added anonymity (to an extent), all enumerated in the link to my program above, in detail...apk
So your anti-virus knows to scan it?
That should take away the incentive for some of the attacks: no money, so less resources to spend on developing attacks!
Hosts != crippled by default advertiser bribed (Adblock) http://it.slashdot.org/comments.pl?sid=4081759&cid=44546757 or advertiser owned tracking by default (Ghostery).
Per my subject-line: Hosts do more for less - Far more listed in the link inside the one above in detail.
(Via less moving parts & complexity + are completely easily end user controlled too!)
Hosts supplement redundant crippled browser-level slower ring 3/rpl 3/usermode tools (since hosts operate in ring 0/rpl 0/kernelmode @ OS startup + 1st webbound request).
Hosts "shore up" dns servers too (overcoming their weakness vs. fastflux + dynDNS botnets abusing dns' very nature & they are by far the more prevalent type out there) & resolve host-domains to IP addresses FASTER, locally (bonus).
APK
P.S.=> Been building my custom hosts file since 1997, & it "clocks in" @ 2,083,016++ & growing entries: If you use my app, yours WON'T be that big (you will have absolutely CURRENT blocks though - the good part on this note @ least...): Far from it if you avoid hostsfilemine.nu (updates yearly only & HUGE, but not absolutely current, my other 11 sources are daily).
Yes - why? It takes TIME to build one that big (took me 16++ yrs. & it's NOT the biggest out there either, airelle's is but TOO full of 'false positives' imo)!
However, I do so unlike others, for good reasons as to the SIZE of mine that I noted above: I don't pull ones others do since they test by 'ping' quite often, & that's EASY to make a system NOT respond reply to, and of course, due to fastflux + dynDNS using botnets/malware... ICANN, or DNS level or firewall outbound/inbound rules can do the rest & it's EASY for them to do so, vs. the far lesser used IP address attacks (I do it via a powershell script here though, that one day? I may build a companion to THIS app for that auto-adds them to firewall rules tables though should IP addressed ones EVER take precedence instead of host-domain based threats)
... apk
... in order to sign the victim up for some premium-rate SMS services.
The fuck?
Why the hell doesn't the FTC shut these companies down? Why doesn't the FCC kick the carrier's behind into policing these companies better? Why doesn't the US attorney's office rain hellfire and brimstone down on these companies to the extent it did to Aaron Schwartz?
Premium SMS is billed through the carriers, so they have a relationship with the SMS company. There is a clear money trail. The recipient is most likely incorporated. This should be easy.
With all the US mistrust of government right now, this would be an easy way to gain some respectability.
As I decided to purchase my first smartphone, I considered a lot of little things. I considered the network, and Verizon had consistently worked for me. I considered the camera, and decided at the time, only Nokia cared about super quality and didn't run on Verizon. I considered tethering and learned that most phones required to either jailbreak or pay for the privilege. But then I saw a phone that wasn't very popular. One which they had to offer tethering to just get the inventory moving. A phone with a real keyboard. And a slick interface. One which let me talk to my gtalk friends out of the box, and put all my email in 1 place. One with an OS about to be gone. A phone with no real applications. And no real reason for malware.
Life is full of choices. It pays to be unpopular.
I pay for a connection: Ads rob speed & bandwidth I paid for out of pocket from said online connection!
Ads ALSO infest systems with maliciously scripted attacks quite a lot - the premise of this article in fact.
This article's example?? No first, by ANY means!
(I literally KNOW of roughly 30 other occurences of it happening BEYOND this single instance example the past, oh 5++ yrs. or so (only, there have been more earlier), & have the likes of CISCO + those like them, showing even more - Want those evidences?? Ask, & "ye shall receive"...).
Additionally - I'll allow what I FEEL I wish to see in my system, as I see fit... advertisers & their "1/2 truths" + "fine print" b.s. be damned.
Sites that can't survive without them? They're WEAK then, & were never in it for anything more than a paycheck (instead of passion for that which their site's premise was founded on initially).
* Without users you're calling leeches, you are HISTORY/done, period... we as customers, however, have options - they're called YOUR COMPETITORS (who'd LOVE to see you fall).
Guess what? You LOSE! Twice in fact - Why? See all of the above. It's THAT simple.
APK
P.S.=> Remember rule #1: "The Customer is ALWAYS right" - why? See above (especially the part about customers always having alternatives/options). You, as a business, CANNOT profitably exist without them/us - fact (not for long @ least since the "raison d'etre" OF business, is profitability)
... apk
Good thing I have sprint, I never get any signal for the virus to send SMS messages, and forget about signing up for any services (useful or not). :/
"Happy families are all alike; every unhappy family is unhappy in its own way." -- Anna Karenina by Leo Tolstoy
"Someone asked him, 'why'. He said: 'The people who're trying to make this world WORSE, are not taking a day off - how can I?' Light up the darkness..." - Dr. Robert Neville from "I AM LEGEND" quoting Bob Marley
That "all said & aside": IF I'm able to help the situation? I do. Do you? NO.
---
"My god" - by Anonymous Coward on Tuesday August 13, 2013 @11:17AM (#44553111)
Quote Dr. Robert Neville again (my theme) keeping w/ the fact there're idiots making malwares online:
"God didn't do this Anna - We DID..." - Dr. Robert Neville from "I AM LEGEND"
Been modded up 4 this post ~ 50x by the way.
---
Above all: VALIDLY disprove my points on hosts' benefits to end-users of them in better added speed, security, reliability, & even anonymity to an extent vs. online threats enumerated here:
http://start64.com/index.php?option=com_content&view=article&id=5851:apk-hosts-file-engine-64bit-version&catid=26:64bit-security-software&Itemid=74
* It's ALL I've ever asked of "naysayer trolls"/detractors!
---
However - No troll here or elsewhere, ever has validly.. Not a 1 & I keep getting stronger for it too (bonus).
(Especially since its output produces 1 file that's tightly integrated as part of the IP stack itself & yet does MORE by far, vs. competing "souled-out" solutions (Ghostery/AdBlock)).
APK
P.S.=> Trolls don't *try* anymore - "Gee, wonder why?" (not - I've floored the "best & brightest" of you 10 below plantlife IQ trolls too many times, you've given up!). I take heart in that fact, & it makes me laugh @ you.
Quoting Dr. Robert Neville again from "I AM LEGEND" regarding the troll, & others like him:
"Behavioral note: An infected male (the troll I am replying to) exposed himself to sunlight today: Now, it's possible decreased brain function (definitely) or growing scarcity of food is causing them to ignore their basic survival instincts. Social De-Evolution is complete: Typical human behavior is now entirely absent..."
... apk
Because the article is bunk?
Applications like GloveBox that overlay on top of the screen are automatically disabled / cease to work during application installs. At worst case (assuming the person unchecked the "Install from Unknown sources" already), they'd have two different application installation screens.
At best case, it just says "APPLICATION BLOCKED" "INSTALL AT YOUR OWN RISK"