Google Removes Plankton Infected Apps http://snapvoip.blogspot.com/
Infection by malware has forced Google to remove ten more apps from the Android Market. The Spyware delivered by various means installs a code known as Plankton on Android devices. The code was detected and reported by Xuxian Jiang, an assistant professor at North Carolina State University's Department of Computer Science.
Earlier this month, Google removed Apps infected by another malware, DDLighr or DroidDream.
"While continuing an Android-related research project after the discovery of the DroidKungFu and YZHCSMS malware, my research team also came across a new stealthy Android spyware in the Official Android Market. This spyware does not attempt to root Android phones but instead is designed to be stealthy by running the payload under the radar. In fact, Plankton is the first one that we are aware of that exploits Dalvik class loading capability to stay stealthy and dynamically extend its own functionality. Our investigation indicates that there are at least 10 infected Android apps in the Official Android Market from three different developers. Its stealthy design also explains why some earlier variants have been there for more than 2 months without being detected by current mobile anti-virus software. " Jiang wrote in his article on the subject.
Webroot Threat blog also wrote about the Plankton after their analysts Andrew Brandt and Armando Orozco investigated the Plankton and discovered that it mostly taking advantage the popular game series Angry Birds. "Some of the samples we looked at came as Android apps with names like Angry Birds Rio Unlocker v1.0, Angry Birds Multi User v1.00 or Angry Birds Cheater Trainer Helper V2.0," they wrote on Threat Blog. According the the researchers, detecting the code was not a major issue and the way it was installed makes it easier to remove the code from the phone.
The developers of the malare developers are elusive at the moment. Always exercise care when you get new apps.
Showing posts with label DroidDream. Show all posts
Showing posts with label DroidDream. Show all posts
Monday, June 13, 2011
Monday, March 7, 2011
Android Market Security Tool March 2011 Aid Android Kill Switch In Fixing DroidDream Nightmare.
In a step to aid the users who were affected by DroidDream malware distributed with Malicious apps, "Android Market Security Tool March 2011" will prevent attackers from accessing any further information by reversing the root access enabled by the rogue apps. Those apps were published by three bad people, “Myournet” “Kingmall2010″ and “we20090202″ and the list of apps available at the above link.
The tool does not patch the exploits the malware apps used but does remove the traces of malicious code left behind when the apps were uninstalled by users or by Android Kill Switch..
Previously, Google remotely deleted the malware infested apps from users phones. Starting last Wednesday Google removed more than 50 infected Android apps from the market place. These rogue applications took advantage of known vulnerabilities which are not present in Android versions 2.2.2 or higher.
If you ever downloaded any of these apps, you would better and safe with this tool;
An Update on Android Market Security - Official Google Mobile Blog
The tool does not patch the exploits the malware apps used but does remove the traces of malicious code left behind when the apps were uninstalled by users or by Android Kill Switch..
Previously, Google remotely deleted the malware infested apps from users phones. Starting last Wednesday Google removed more than 50 infected Android apps from the market place. These rogue applications took advantage of known vulnerabilities which are not present in Android versions 2.2.2 or higher.
If you ever downloaded any of these apps, you would better and safe with this tool;
You can learn more at the Android Market Help Center. Be safe and enjoy your Droid Phones.
- We removed the malicious applications from Android Market, suspended the associated developer accounts, and contacted law enforcement about the attack.
- We are remotely removing the malicious applications from affected devices. This remote application removal feature is one of many security controls the Android team can use to help protect users from malicious applications.
- We are pushing an Android Market security update to all affected devices that undoes the exploits to prevent the attacker(s) from accessing any more information from affected devices. If your device has been affected, you will receive an email from android-market-support@google.com over the next 72 hours. You will also receive a notification on your device that “Android Market Security Tool March 2011” has been installed. You may also receive notification(s) on your device that an application has been removed. You are not required to take any action from there; the update will automatically undo the exploit. Within 24 hours of the exploit being undone, you will receive a second email.
- We are adding a number of measures to help prevent additional malicious applications using similar exploits from being distributed through Android Market and are working with our partners to provide the fix for the underlying security issues.
An Update on Android Market Security - Official Google Mobile Blog
Subscribe to:
Posts (Atom)