3-in-1 Android Malware Acts As Ransomware, Banking Trojan and Info Thief
An anonymous reader writes: Why stop at asking ransom for encrypted files when you can also steal personal info, passwords, online banking credentials and credit card details, and sell it or use it to get even more money? Palo Alto researchers have recently analyzed Xbot, a Trojan that is capable of doing all the aforementioned things, and have found it mimicking 22 different Android apps.
Good grief:
The malware does encrypt files, but it does so by simply XORing each byte in all files by the fixed integer number 50. That means that the malware’s claims that the files can’t be decrypted without paying the ransom and receiving the decryption key is not true.
The actual article is here:
http://researchcenter.paloalto...
If it steals banking info, it should automatically log in to your bank and pay the ransom itself.
100% correct. If you look more closely these "researchers" are actually Palo Alto Networks who will sell you a device that "protects" you from this. If you look at the threat it screams scam: there are .ru URLs where you need to enter your credit card information into all over the place. I doubt anyone would be dumb enough to fall for this.
I know people like shiny things - but Android is a security nightmare. Really - friends don't let friends use Android.
I have read this so many times this doesn't even qualify as a good troll. Most operating systems nowadays are secure enough so long as you observe a number of commonsense security habits, like: Don't visit shady sites. If you have to, remember the old advice about not eating where you poop. Use a different device to browse porn and to bank online. Don't use a heavily modded or tampered device unless you absolutely know what you're doing. This includes the installation of "cracked" apps and root kits recommended by some pseudonymous forum member.
...there are .ru URLs where you need to enter your credit card information
Oh yeah, that's something I'd do without hesitation, lol. No one in Russia would ever do anything bad with my credit card number.
Just cruising through this digital world at 33 1/3 rpm...
Yeah, about that:
Turn that to "general public", and you see where we're at.
These things work because people do fall for them.
Lost at C:>. Found at C.
Don't sideload apps from untrusted sources. 99.9% of your android problems cease to exist if you follow that 1 piece of advice. Sadly, being 2.2 (omg!!) you are pretty screwed regardless of how safe you play it, replace it dude, most companies offer trade ups and such, I'm not even saying stick with android, but something that old and unpatched is not worth the risk unless you literally use it for phone calls and phone calls alone.