Slashdot Mirror


Android Botnet Evolves, Could Pose Threat To Corporate Networks

angry tapir writes An Android Trojan program that's behind one of the longest running multipurpose mobile botnets has been updated to become stealthier and more resilient. The botnet is mainly used for instant message spam and rogue ticket purchases, but it could be used to launch targeted attacks against corporate networks because the malware allows attackers to use the infected devices as proxies, according to security researchers.

11 of 54 comments (clear)

  1. Root Your Device? by theshowmecanuck · · Score: 2

    Is this a good reason to root your device so you can put a decent firewall on it? At the least block its communication if it installs itself. Or is it known to change firewall settings too?

    --
    -- I ignore anonymous replies to my comments and postings.
    1. Re:Root Your Device? by Lussarn · · Score: 4, Informative

      Don't install random crap from the internet. If you use play store the chance is virtually nil to be infected with malware. You also have to make the active choice to even be able to install these trojans by ticking "non trusted sources" down in preferences.

      It isn't exactly hard to keep an Android device malware free. Same as any other operating system with a good selection of programs in the default repos and stores, like Debian, Ubuntu, or OS X. Even if those operating systems don't mandate one supplier of programs only.

      If this sounds to hard, just use iPhones and Playstations which are unable to install random crap no matter how much you need it, but at least you're safe.

    2. Re:Root Your Device? by DrXym · · Score: 3, Funny

      I guess someone would have to tell us how to detect it, or something else equally helpful to actually PREVENT this threat. Warnings are pointless without a plan.

      Just google for "free antivirus and sexy girl screensaver APK". Lots of Chinese warez sites have it. The app asks for a lot of permissions but only to see if there are viruses hiding in your text messages or contacts.

    3. Re:Root Your Device? by mlts · · Score: 2

      It depends on how savvy the person is. If one has basic UNIX abilities, then yes. Set a firewall, set it to not allow anything out unless it is explicitly granted by you.

      Even better, using Xposed's XPrivacy is also a major security boost. If some flashlight app is demanding root, trying to get to contacts, trying to get to sites offshore, it will be obvious to the user and thus stopped.

      Of course, if the user isn't UNIX savvy, they may end up blocking some outgoing task that needs to phone home and then get mad why their phone isn't working.

      As for the malware, if it is an app, the worst it can do is try to install itself as a device administrator (which will require a prompt from the user) which gives it the ability to lock and erase the device at will, as well as the ability to hide itself. Of course, if the user has a rooted device and allows the app access via su, the game is over. However, newer su versions will disallow apps from even prompting for su access unless they declare a permission for it (ACCESS_SUPERUSER) which will be obvious when downlaoded or installed.

  2. Use Meetspace as a firewall by Anonymous Coward · · Score: 3, Insightful

    Is this a good reason to root your device so you can put a decent firewall on it? At the least block its communication if it installs itself. Or is it known to change firewall settings too?

    FTA.

    Users would then see notifications about the finished downloads and would click on them, prompting the malicious application to install if their devices had the "unknown sources" setting enabled

    ie: Stupid is as stupid does...
    That's like lusers complaining about malware installed on the Windo$e PC being they turned off UAC.

  3. Oh, for a successor to Open Moko by Ungrounded+Lightning · · Score: 3, Interesting

    I'm still waiting for a truly open-source, unlocked, user-controllable phone. Like a successor to Open Moko. (Building a closed platform on a base of open software doesn't cut it.)

    Is anything out there or in the works?

    (It's particularly acute for me just now: My decade-old feature phone started to flake out last week.)

    --
    Bantam Dominique roosters crow a four-note song. Once you've heard it as "Happy BIRTHday" you can't NOT hear it that way
    1. Re:Oh, for a successor to Open Moko by stoborrobots · · Score: 3, Informative

      OnePlus One? http://oneplus.net/

    2. Re:Oh, for a successor to Open Moko by Anonymous Coward · · Score: 2, Insightful

      I have an OPO and I wouldn't recommend it to anyone.
      The Synaptics touch driver still doesn't work.
      The call volume is broken from launch.
      Can't even name one good thing about it. Pure lemon.
      It's almost worse than early HTC phones that didn't even have drivers.

  4. key words by Neil+Boekend · · Score: 4, Insightful

    if their devices had the "unknown sources" setting enabled.

    That is an advanced user setting. It should not be changed unless the user is certain. It even triggers a warning if you change it.
    Only change that if you are certain you can use the device safely without it.
    If you can't, then leave it in it's factory setting.

    Stupid is as stupid does.

    --
    Well, I might have a way, but it only works on a semi spherical planet in a vacuum.
  5. Corporate networks.... really? by Reprint001 · · Score: 4, Informative

    "could be used to launch targeted attacks against corporate networks" A corporate network operator that allows BYOD Android devices with no MDM installed, direct network access deserves an attack. And corporately owned Android devices would normally have a secure MDM installed with settings like "unknown sources" disabled and not user changeable. For this malware to get access to a corporate network it would require some really poor security practices on the part of the device owner and network owner which would probably mean the company were vulnerable to much simpler attacks.

  6. Re:Wisdom follows, pay attention! by amalcolm · · Score: 2

    Shill

    --
    Time for bed, said Zebedee - boing