Android Botnet Evolves, Could Pose Threat To Corporate Networks
angry tapir writes An Android Trojan program that's behind one of the longest running multipurpose mobile botnets has been updated to become stealthier and more resilient. The botnet is mainly used for instant message spam and rogue ticket purchases, but it could be used to launch targeted attacks against corporate networks because the malware allows attackers to use the infected devices as proxies, according to security researchers.
Is this a good reason to root your device so you can put a decent firewall on it? At the least block its communication if it installs itself. Or is it known to change firewall settings too?
-- I ignore anonymous replies to my comments and postings.
Is this a good reason to root your device so you can put a decent firewall on it? At the least block its communication if it installs itself. Or is it known to change firewall settings too?
FTA.
Users would then see notifications about the finished downloads and would click on them, prompting the malicious application to install if their devices had the "unknown sources" setting enabled
ie: Stupid is as stupid does...
That's like lusers complaining about malware installed on the Windo$e PC being they turned off UAC.
What more could you want than open windows and doors to your vault of info.
>> "encrypts its communications with the C&C servers, making the traffic indistinguishable from legitimate SSL, SSH or VPN traffic"
Um...if you think simple transport encryption stops a determined analyst (who can hone in on source/destination IPs, initial traffic patterns, traffic volume, local signals or can use an attack proxy for some MITM action)...think again.
I'm still waiting for a truly open-source, unlocked, user-controllable phone. Like a successor to Open Moko. (Building a closed platform on a base of open software doesn't cut it.)
Is anything out there or in the works?
(It's particularly acute for me just now: My decade-old feature phone started to flake out last week.)
Bantam Dominique roosters crow a four-note song. Once you've heard it as "Happy BIRTHday" you can't NOT hear it that way
if their devices had the "unknown sources" setting enabled.
That is an advanced user setting. It should not be changed unless the user is certain. It even triggers a warning if you change it.
Only change that if you are certain you can use the device safely without it.
If you can't, then leave it in it's factory setting.
Stupid is as stupid does.
Well, I might have a way, but it only works on a semi spherical planet in a vacuum.
"could be used to launch targeted attacks against corporate networks" A corporate network operator that allows BYOD Android devices with no MDM installed, direct network access deserves an attack. And corporately owned Android devices would normally have a secure MDM installed with settings like "unknown sources" disabled and not user changeable. For this malware to get access to a corporate network it would require some really poor security practices on the part of the device owner and network owner which would probably mean the company were vulnerable to much simpler attacks.
Shill
Time for bed, said Zebedee - boing
You would lose that bet
Time for bed, said Zebedee - boing
It's not that there are not enough viable alternatives to Overlord Google.
We suffer more in our imagination than in reality. - Seneca
Beats me. I get my free stuff for free.
Can we just for once stop using terms like "evolved" as if this thing has any kind of ability to mutate outside of the agency of people - intelligent designers if you will - actually making changes to the code.
Yay! The botnet of things! :)
It's my f#$@ing phone. If I want root on my own phone, I should be able to get it, just like I can get root on my home computer.
But the only way to root, say, the Galaxy S5 is to run an older version of the kernel.. a version vulnerable to a root exploit. The exploit of course allows OTHERS to root the phone if I'm not careful, but installing ANY security updates or upgrading the OS on the phone fixes the "flaw" that gives me root.
So the only way to get root is to leave my phone running older, insecure software.
All because these shitty companies go ballistic at the thought of the user being the administrator of his own device.