Aggressive Android trojan SMSZombie detected in China
|
by Anuradha Shetty
|
|
Analysts at TrustGo Security Labs have discovered the Trojan!SMSZombie.A, a new trojan, according to an official blog post. It is a complex and sophisticated malware that exploits a vulnerability in the China Mobile SMS Payment System to fund unauthorised payments, steal bank card numbers and receipt information regarding money transfers. The trojan is difficult to detect, and even more difficult to remove. The malicious code piggybacks on a wallpaper app found in GFan, China's largest Android marketplace. The trojan installs itself on a device after its user has downloaded and installed the app, making detection difficult. As a result, the wallpaper app is not flagged as malicious in the marketplace. Further, the trojan can change the amount and timing of unauthorised charges; that way most times users don't know that they have been hacked. ![]() Researchers discover difficult to detect malware
Through the course of investigation, researchers at TrustGo found that the malware is used to recharge online gaming accounts of the hackers via the China Mobile SMS Payment System. To avoid being caught, the amount wiped out is usually relatively low.
Once installed, the app is potent enough to terminate a user's ability to remove it or disable it. The blog post has listed a number of packages in which it can be found -- com.ldh.no1, com.lzll.pic, com.xqxmn18.pic, com.gmdcd.pic, com.gsjnqt1.pic, com.zqbb1221.pic and com.bntsxdn.pic.
The blog post reveals that the wallpaper app in which the malware has been concealed gets the users' attention with provocative titles and images. Once a user sets one of the wallpapers as the device's wallpaper, the app further asks the user to install more files associated with the trojan. If the user agrees, then the payload included in a file called 'Android System Service' is installed. Then the malware attempts to get administrator privileges on the device. Here, a user cannot cancel the step and deny administrator access to the malware. Hitting the "Cancel" button causes the dialog box to keep reappearing until the user chooses "Activate". This way, users find themselves unable to delete or disable the app.
Researchers have found that by using a configuration file, which can be updated by the makers of the malware at any time, it is possible for the malware to intercept and forward text messages. As SMSes sometimes include banking information and other financial details, the malware can wreak further havoc in user accounts.
Know more about the trojan.
Cover Image credit: Getty Images |
Tags: Android malware , Android platform , TrustGo Security Labs , Trojan!SMSZombie.A , China Mobile SMS Payment system , online gaming accounts
SPOTLIGHT
If Huawei acquires Nokia, Windows Phone is...
19 Jun, 2013, 12:35 PM
Instagram video could be Facebook's...
19 Jun, 2013, 09:25 AM
Apple could add LinkedIn integration to iOS
19 Jun, 2013, 12:43 PM
No delivery, says Flipkart for Rs 10,000-plus orders from UP
07 Jun, 2013, 11:07 AM IST
Mumbai movie-goers breathe sigh of relief after online Convenience...
17 Jun, 2013, 09:01 PM IST
Vietnam arrests well-known blogger for criticising the Government
14 Jun, 2013, 09:56 AM IST
Mumbai Police's latest headache: ATM skimming explained
15 Jun, 2013, 04:25 PM IST
While working for spies, Snowden was secretly prolific online
15 Jun, 2013, 10:19 AM IST
Icahn changes tack, seeks $16 billion Dell stock buyback
19 Jun, 2013, 08:30 AM
Microsoft says it freed millions of computers from criminal botnet
19 Jun, 2013, 08:20 AM
WikiLeaks trial focuses on whether Tweets meet evidence standards
19 Jun, 2013, 08:14 AM
How IRCTC can make tatkal bookings easier
In India, online travel ticketing has gotten mature and more Indians are...
Looking for food past midnight? Check out these services
Struck by midnight hunger pangs? Check these services that will bring...
Best online resources for CAT preparation
Take a look at the best free and paid resources for CAT preparation...
Sony Xperia tipo dual (ST21i2) Review
SG Babu
Wed Jun 19, 12:37:40
PlayStation 4 first party titles to cost the same as Xbox One games
Stark
Wed Jun 19, 12:06:56
PlayStation 4 up for pre-order in India
Rup kumar
Wed Jun 19, 12:02:30
If Huawei acquires Nokia, Windows Phone is
Samsung’s Tizen smartphones to be...
Sony Xperia Tablet Z (SGP321) Review
iBall launches Slide 3G-7334i tablet for...
New MacBook Air coming soon to India;...
Alienware shows three new gaming notebooks
Humble Bundle with Android 6 now available
Call of Duty: Black Ops 2 to get Vengeance


















reddit

Mixx
Facebook
Twitter
Digg
delicious
MySpace















