Softpedia
 

NEWS CATEGORIES:



NEWS ARCHIVE >>
SOFTPEDIA REVIEWS >>
MEET THE EDITORS >>
Home > News > Security

July 14th, 2011, 16:19 GMT · By

Android Trojans Pose as Legit Security Applications

SHARE:

Adjust text size:


Android trojans spoof legit security applications
Enlarge picture
Android malware authors have began passing their creations as legit security applications, trojans posing as Kaspersky Anti-Virus and Trusteer Rapport being seen so far.

Spoofing security software is common with desktop threats, particularly scareware applications that immitate antivirus programs. However, the trend is relatively new with mobile malware.

The Android trojan that poses as the Trusteer Rapport security application is actually the new ZeuS-in-the-mobile (Zitmo) variant discovered by security researchers recently.

Researchers from Kaspersky have found web pages generated by a desktop ZeuS variant which informs users about a new mobile security app for online banking.

Users are asked to choose their mobile operating system and if Android is selected, they are served an .apk file which installs the fake Rapport application.

The application is actually quite simple. It monitors SMS messages and send copies of them to a remote server. This is done in order to intercept mobile transaction authentication numbers (mTANs).

Meanwhile, security researchers from Sophos have came across an Android trojan that poses as Kaspersky Anti-Virus 2011. The application appears to be a test and not an actual malicious trojan, but is a good indication that malware creators are juggling with the idea of impersonating security vendors.

Similarly to the Zitmo component, after installation, the fake Kaspersky app tries to generate and display an activation code. After this it, it intercepts SMS messages and sends them to a remote server.

"Luckily, in the case of this malware (which Sophos detects as Andr/SMSRep-C), the command-and-control web server IP address is 127.0.0.1 (localhost), which does not make the malware very useful.

"Clearly, this is just an early test build and we will have to be on watch for the next version which will be connected with a real malicious server," concludes Vanja Svajcer, a principal virus researcher at SophosLabs.

TELL US WHAT YOU THINK:

1,487 hits · Link to this article · Print article · Send to friend · Subscribe to news

MUST-READ RELATED ARTICLES:


Zbot Targets Android Users

New Android Spyware Can Switch C&C Servers

New Android Spyware Capable of Relaying SMS Messages

New Trojan Targets Custom Android ROMs

New Android Malware Found in Official Market Apps

READER COMMENTS:



No user comments yet.
Be the first to express your opinion!
Copyright © 2001-2012 Softpedia. Contact/Tip us at

WindowsGamesDriversMacLinuxScriptsMobileHandheldNews

SUBMIT PROGRAM   |   ADVERTISE   |   GET HELP   |   SEND US FEEDBACK   |   RSS FEEDS   |   UPDATE YOUR SOFTWARE   |   ROMANIAN FORUM