Will Verduzco · Jan 24, 2014 at 02:00 pm

New Windows Malware Infects Android Devices; Protect Yourself with Two Easy Steps

Cross-platform malware is nothing new. And to be more specific, cross-platform malware involving the Android OS isn’t new either. This should come as no surprise, as the pint-sized mobile OS packs nearly as much functionality and freedom as its full-sized brethren.

Some time ago, we saw the Android.Claco trojan. This particular piece of malware used a compromised mobile device to transfect your Windows-powered PC by functioning as a malicious USB drive. Upon connection via USB Mass Storage, Windows AutoRun would then automatically execute the malicious payload.

Up until recently, however, the only cross platform malware involving Android that we’ve seen in the wild has involved infected Android devices targeting desktop computers. Now, Symantec has spotted a new trojan targeting Android devices from infected Windows computers.

The new malware is known as Trojan.Droidpak, and it essentially works by using ADB to install a malicious APK (variant of the previous Android.Fakebank.B trojan) that poses as the Google Play Store (“Google App Store” in the screenshot). Then once run, the malicious APK searches for specific Korean online banking apps. If these apps are found, the malware prompts the user to delete the originals and install malicious versions. It also intercepts and reroutes SMS messages on compromised devices to a predetermined location, presumably to intercept fraud protection messages from said banking institutions.

While this specific piece of malware poses very little concrete threat to those outside of Korea who do not rely on the select banking institutions targeted by the trojan, it is entirely possible that similar attacks exist in other regions, targeting other demographics. This highlights the importance of always being cautious and disabling unnecessary services. Furthermore, users should always exercise caution when connecting their mobile devices to unknown computers.

You can learn more about the specifics by visiting the Symantec Malware Bulletin. But first, make sure you protect yourself by disabling unnecessary services such as USB Debugging and only connecting to trusted computers. Furthermore, do yourself a favor and enable verify apps.

Has Android malware been an issue for you in the past? We’ve seen some evidence suggesting that it largely isn’t an issue for most users due to Android’s multiple layers of defense. However, this new type of attack could potentially bypass these measures on devices with USB debugging enabled and verify apps disabled. Let us know your thoughts on Android malware in the comments below!

[Many thanks to XDA Forum Member dr.eXntriK for the tip!]


_________
Want something on the XDA Portal? Send us a tip!
TAGS:

Will Verduzco

willverduzco is an editor on XDA-Developers, the largest community for Android users. Will Verduzco is the Portal Administrator for the XDA-Developers Portal. He has been addicted to mobile technology since the HTC Wizard. But starting with the Nexus One, his gadget love affair shifted to Google's little green robot. He is also a Johns Hopkins University graduate in neuroscience and is now currently studying to become a physician. View willverduzco's posts and articles here.
Mario Tomás Serrafero · May 25, 2015 at 02:00 pm · 2 comments

XDA Office Space: Frankenstein’s Perfect IM Client?

The portal’s decentralized XDA office lies in a Hangouts chatroom, where we discuss the latest developments that hit the blogosphere, critique them and figure out what we can do to add a new or original point of view. We came to love this little virtual office, which sees messaging 24/7 due to the international nature of our team. The main problem that we have faced since early on is that Hangouts is not versatile enough for in-depth discussion.   What...

XDA NEWS
Emil Kako · May 25, 2015 at 12:32 pm · 4 comments

Which IM Client on Android is best?

With so many different messengers to choose from, it can be tough to find the best one for you and your friends to use. Hangouts, Whatsapp, Telegram and more are all battling it out for the number one spot. Let us know which IM client you think is best on Android and why.

DISCUSS
Jimmy McGee · May 25, 2015 at 12:00 pm · 2 comments

Android Factory Reset Security Flaw and More – XDA TV

Nvidia is releasing a 500Gb SHIELD TV Pro! That and much more news is covered by Jordan when he reviews all the important stories from this weekend. Included in this weekend's news is the announcement of an Android factory reset security flaw and be sure to check out the article talking about the Nexus Player getting TWRP. That's not all that's covered in today's video! Jordan covered the LG G4 First Impressions and Unboxing video from TK released this weekend...

XDA NEWS
Share This