• About Us
  • Contact Us
  • Cookie policy (EU)
  • Home
  • Privacy Policy
  • Video
  • Write for us
Today Headline
  • HOME
  • NEWS
    • POLITICS
  • FINANCE
  • Video
  • ENTERPRISE
  • TECHNOLOGY
  • ENTERTAINMENT
  • LIFESTYLE
    • TRAVEL
    • HEALTH
  • AUTOMOTIVE
  • SPORTS
  • Write for us
  • HOME
  • NEWS
    • POLITICS
  • FINANCE
  • Video
  • ENTERPRISE
  • TECHNOLOGY
  • ENTERTAINMENT
  • LIFESTYLE
    • TRAVEL
    • HEALTH
  • AUTOMOTIVE
  • SPORTS
  • Write for us
No Result
View All Result
TodayHeadline
No Result
View All Result
Home Technology

A new advanced Android malware posing as system update

March 28, 2021
in Technology
0
A new advanced Android malware posing as system update
0
SHARES
221
VIEWS
Share on FacebookShare on Twitter


A new advanced Android malware posing as system update

AndroidManifest malware. Credit: Zimperium

In recent weeks, Zimperium zLabs researchers revealed unsecured cloud configurations exposing user data across thousands of legitimate Android and iOS applications. Now, zLabs is advising Android users about a clever and malicious new Android app.

This latest malware takes the form of a System Update application in order to steal data, images, messages and usurp control over entire Android phones. After assuming control, attackers can record audio and phone calls, view browser history, take photos and access WhatsApp messages, among other activities.

zLabs researchers uncovered this alleged System Update app after detecting an application flagged by the z9 malware engine powering zIPS on-device detection. An investigation showed this activity to trace to an advanced spyware campaign with intricate capabilities. Researchers sealed the deal after confirming with Google that such an app never existed nor was planned to ever be released on Google Play.

With an extensive list of compromise capabilities, this malware can steal messages off instant messenger systems and their database files using root, examine the default browsers bookmarks and searches, inspect bookmark and search history from Google Chrome, Mozilla Firefox and Samsung Internet browsers, search for files with the specific extensions .doc, .docx, .pdf, .xls and .xlsx; examine clipboard data and notifications content, take periodic photos via the front or rear camera, view installed applications, steal images and video, monitor via GPS, steal phone contacts and SMS messages as well as call logs and exfiltrate device information such as device name and storage data. Moreover, the malware can even conceal itself by hiding its icon from the devices’ menu.

This malware works by running on Firebase Command and Control (C&C) upon installation from a non-Google third party apps store, listed under the names “update” and “refreshAllData”. To enhance its sense of legitimacy, the app contains feature information such as the presence of WhatsApp, battery percentage, storage statistics, type of Internet connection and Firebase messaging service token. Once the user selects to “update” the existing information, the app infiltrates the affected device. Upon dissemination, the C&C receives all relevant data, including the new generated Firebase token.

While the Firebase communication makes the necessary commands, the dedicated C&C server uses a POST request to gather the stolen data. Notable actions that trigger exfiltration by the app include adding a new contact, installing a new application via Android’s contentObserver or receiving a new SMS.


Unsecured cloud configurations expose data across thousands of mobile apps


More information:
Yaswant, A. “New Advanced Android Malware Posing as ‘System Update.'” Zimperium Mobile Security Blog, Zimperium, 26 Mar. 2021, blog.zimperium.com/new-advance … ng-as-system-update/

© 2021 Science X Network

Citation:
A new advanced Android malware posing as system update (2021, March 28)
retrieved 28 March 2021
from https://techxplore.com/news/2021-03-advanced-android-malware-posing.html

This document is subject to copyright. Apart from any fair dealing for the purpose of private study or research, no
part may be reproduced without the written permission. The content is provided for information purposes only.

 
 
   
Tags: AdvancedAndroidMalwareposingSystemupdate
Previous Post

Busting Covid myths: Why those Covid temperature tests aren't just pointless - they're dangerous

Next Post

The U.S.-Mexico Vaccine Deal Is Inciting a Brutal Migrant Crackdown

Related Posts

Telling sunbathers what they don’t want to hear: Tanning is bad
Technology

Telling sunbathers what they don’t want to hear: Tanning is bad

Defective freeloader genomes unmasked in DNA virus infections
Technology

Defective freeloader genomes unmasked in DNA virus infections

Reuters exclusively reports software vendors would have to disclose breaches to U.S. government users under new order
Technology

Reuters exclusively reports software vendors would have to disclose breaches to U.S. government users under new order

A note of crypto caution
Technology

A note of crypto caution

‘Final Fantasy’ maker Square Enix denies sale reports
Technology

‘Final Fantasy’ maker Square Enix denies sale reports

Social wasps lose face recognition abilities in isolation
Technology

Social wasps lose face recognition abilities in isolation

Next Post
The U.S.-Mexico Vaccine Deal Is Inciting a Brutal Migrant Crackdown

The U.S.-Mexico Vaccine Deal Is Inciting a Brutal Migrant Crackdown

  • Trending
  • Comments
  • Latest
Now Moderna vaccine sparks blood clot fears as patient shares how he thought he was going to die

Now Moderna vaccine sparks blood clot fears as patient shares how he thought he was going to die

Fast radio bursts: Mysterious signals coming from distant parts of the universe are ‘deeper’ than we realised, scientists say

Fast radio bursts: Mysterious signals coming from distant parts of the universe are ‘deeper’ than we realised, scientists say

DR MICHAEL MOSLEY: Should doctors now prescribe dummy pills to ease pain?

DR MICHAEL MOSLEY: Should doctors now prescribe dummy pills to ease pain?

Where is Pickle Cottage? The Essex Mansion Stacey Soloman bought for £1.2M – and how it got its name

Where is Pickle Cottage? The Essex Mansion Stacey Soloman bought for £1.2M – and how it got its name

Meghan Markle news latest – Queen scraps military uniform dress for royals to avoid embarrassment for Harry

Woman who died from blood clots linked to AstraZeneca Covid vaccine

Woman who died from blood clots linked to AstraZeneca Covid vaccine

How to plant and grow tulips for a stunning display – The Middle-Sized Garden

How to plant and grow tulips for a stunning display – The Middle-Sized Garden

Can an IPhone Be Hacked? a Breakdown of Common Hacks

Can an IPhone Be Hacked? a Breakdown of Common Hacks

‘Black Panther II’ will not leave Georgia despite voting laws

‘Black Panther II’ will not leave Georgia despite voting laws

Cheetah Mobile: AI Investments To Eventually Bear Fruit

Cheetah Mobile: AI Investments To Eventually Bear Fruit

Top remaining NFL free agents at each position: Richard Sherman, Larry Fitzgerald headline big names left

Top remaining NFL free agents at each position: Richard Sherman, Larry Fitzgerald headline big names left

Top remaining NFL free agents at each position: Richard Sherman, Larry Fitzgerald headline big names left

Top remaining NFL free agents at each position: Richard Sherman, Larry Fitzgerald headline big names left

Final preparations under way for Duke of Edinburgh’s funeral

Telling sunbathers what they don’t want to hear: Tanning is bad

Telling sunbathers what they don’t want to hear: Tanning is bad

Queen to have final moment with Prince Philip before funeral

Queen to have final moment with Prince Philip before funeral

Data gap threatens to complicate Johnson & Johnson vaccine pause

Data gap threatens to complicate Johnson & Johnson vaccine pause

About Us

Todayheadline the independent news and topics discovery
A home-grown and independent news and topic aggregation . displays breaking news linking to news websites all around the world.

Follow Us

Latest News

‘Black Panther II’ will not leave Georgia despite voting laws

‘Black Panther II’ will not leave Georgia despite voting laws

Cheetah Mobile: AI Investments To Eventually Bear Fruit

Cheetah Mobile: AI Investments To Eventually Bear Fruit

‘Black Panther II’ will not leave Georgia despite voting laws

‘Black Panther II’ will not leave Georgia despite voting laws

Cheetah Mobile: AI Investments To Eventually Bear Fruit

Cheetah Mobile: AI Investments To Eventually Bear Fruit

Top remaining NFL free agents at each position: Richard Sherman, Larry Fitzgerald headline big names left

Top remaining NFL free agents at each position: Richard Sherman, Larry Fitzgerald headline big names left

  • Real Estate
  • Education
  • Parenting
  • Cooking
  • Home garden
  • Pets
  • Privacy & Policy
  • Contact
  • Write for us
  • About

© 2021 All rights are reserved Todayheadline

No Result
View All Result
  • Real Estate
  • Education
  • Parenting
  • Cooking
  • Home garden
  • Pets
  • Privacy & Policy
  • Contact
  • Write for us
  • About

© 2021 All rights are reserved Todayheadline