Softpedia
 

NEWS CATEGORIES:



NEWS ARCHIVE >>
SOFTPEDIA REVIEWS >>
MEET THE EDITORS >>
Home > News > Security

July 7th, 2011, 18:13 GMT · By

New Android Spyware Can Switch C&C Servers

SHARE:

Adjust text size:


GoldDream Android trojan can update itself
Enlarge picture
Security researchers have identified a new piece of Android spyware which spreads via repackaged applications and is capable of switching between different command and control servers.

Dubbed GoldDream, the trojan was discovered on alternative Android markets by Xuxian Jiang, assistant professor in the NC State University's department of computer science.

The peice of malware is designed to spy on victims by uploading their call log and SMS messages to a remote server.

In addition, the trojan notifies the attacker when a call is initiated or when an SMS message is received. It acts like a botnet client that can receive commands remotely.

According to the security researcher, GoldDream can be ordered to send SMS messages, make phone calls, install or uninstall apps and upload a file to a remote server.

Malware analysts from Trend Micro note that the spyware has an unusual ability to update itself and change its command and control servers.

Most Android trojans seen in the past had harcoded C&C URLs, however, the attackers behind GoldDream probably wanted more flexibility in case their primary server goes down.

This sort of redundancy mechanism is typical of desktop trojans that function as part of botnets, however, it has lacked from the mobile threat landscape so far.

The practice of repackaging legit apps with trojans remains the most popular method of distributing Android malware. People should pay attention to the permissions requested upon installation, because trojanized apps need extensive access.

Even though GoldDream was found on private forums distributing apps, Installing only applications from the official Android Market will not guarantee protection from these attacks.

Many Android trojans were originally identified on alternative markets and then made their way to the official one. Google has removed tens of trojanized apps so far from their website and even used remote uninstall commands on some occasions.

TELL US WHAT YOU THINK:

2,137 hits · Link to this article · Print article · Send to friend · Subscribe to news

MUST-READ RELATED ARTICLES:


Android Malware Delivery Techniques Used for Advertising Fraud

New Android Spyware Capable of Relaying SMS Messages

New Trojan Targets Custom Android ROMs

New Android Malware Found in Official Market Apps

New Android Malware Packs Encrypted Root Exploits

READER COMMENTS:



No user comments yet.
Be the first to express your opinion!
Copyright © 2001-2012 Softpedia. Contact/Tip us at

WindowsGamesDriversMacLinuxScriptsMobileHandheldNews

SUBMIT PROGRAM   |   ADVERTISE   |   GET HELP   |   SEND US FEEDBACK   |   RSS FEEDS   |   UPDATE YOUR SOFTWARE   |   ROMANIAN FORUM