• Login:

Welcome to the Xoom Forum - Motorola Xoom Forum.

Register ButtonIf this is your first visit, be sure to check out the FAQ by clicking the link above. You may have to register before you can post: click the register link above to proceed.

First Site With Android Drive-By Malware Spotted

This is a discussion on First Site With Android Drive-By Malware Spotted within the Off-Topic Forum forums, part of the Off-Topic Area category; Lookout Security has spotted websites serving up the very first Android drive-by malware. Lookout Security reports that the firm has identified several sites that are ...

+ Reply to Thread
Results 1 to 4 of 4
Like Tree1Likes
  • 1 Post By ggrant3876

Thread: First Site With Android Drive-By Malware Spotted

  1. #1
    Administrator

    Member #
    2101
    Join Date
    Mar 2011
    Location
    Wichita Falls
    Posts
    34,234
    Liked
    2181 times
    Twitter
    mgrant76308

    First Site With Android Drive-By Malware Spotted

    Lookout Security has spotted websites serving up the very first Android drive-by malware.

    Lookout Security reports that the firm has identified several sites that are serving up malware specifically targeting the Android platform. This means anyone with an unprotected Android device will begin to download the NotCompatible malware when they visit an infected site. The drive-by download is automatic via the system's web browser.

    "When the suspicious application finishes downloading, the device will display a notification prompting the user to click on the notification to install the downloaded app," Lookout reports. "In order to actually install the app to a device, it must have the 'Unknown sources' setting enabled (this feature is commonly referred to as 'sideloading'). If the device does not have the unknown sources setting enabled, the installation will be blocked."

    Android users who have "unknown sources" enabled typically purchase their apps from non-Google Play sources like Amazon's Appstore or GetJar. And even though Google Play can play host to disguised malware despite Google's best efforts, device infection typically takes place because users install non-Google Play apps on their device, especially when downloading from shady repositories.

    But in this case, the user simply visits a website voluntarily and downloads the malware. To prevent installation, users are suggested to switch off the "install from unknown source" setting, but again that locks them out of legit markets. The alternative is to install a security client like Lookout's own service which blocks NotCompatible, and not install APK files that that weren't voluntarily downloaded.

    Still, the drive-by infection sounds epidemic in regards to the number of websites playing host to the drive-by malware. "We’re still in the process of assessing the full extent of infected sites; however, there are early indications that the number of affected sites could be numerous," the firm states.

    Later Lookout said that NotCompatible is a new Android trojan that appears to serve as a simple TCP relay / proxy while posing as a system update. There doesn't seem to be any evidence that it will cause harm to the device, but it could potentially be used to turn an infected Android device into a proxy and gain illicit access to a private network.

    "This specific sample, while relatively well constructed, does not appear to go to great lengths to hide its intended purpose: it can be used to access private networks. This feature in itself could be significant for system IT administrators: a device infected with NotCompatible could potentially be used to gain access to normally protected information or systems, such as those maintained by enterprise or government."

    Lookout said the trojan would have to be installed manually by the end-user, fooled by the "update.apk" name.

    First Site With Android Drive-By Malware Spotted
    kayote likes this.

    SGS-IV-Stock_Rooted
    Nexus 4 - CyanMod 10.1
    SGS-II - Rooted - Jedi Mind Trick VX3
    Samsung Note II - Jedi Master 13
    Motorola Xoom - WiFi - Rooted - EOS 4.2.1 Nightlies

  2. # ADS
    Ads


  3. #2
    Developer

    Member #
    22190
    Join Date
    Mar 2012
    Location
    London, UK
    Posts
    626
    Liked
    187 times
    The answer is surely to switch on "unknown sources" only when you need it, then switch it straight off again.

  4. #3
    Administrator

    Member #
    2101
    Join Date
    Mar 2011
    Location
    Wichita Falls
    Posts
    34,234
    Liked
    2181 times
    Twitter
    mgrant76308
    Quote Originally Posted by zigackly View Post
    The answer is surely to switch on "unknown sources" only when you need it, then switch it straight off again.
    That's exactly what I did, not so hard to get to setting to check and uncheck it.

    SGS-IV-Stock_Rooted
    Nexus 4 - CyanMod 10.1
    SGS-II - Rooted - Jedi Mind Trick VX3
    Samsung Note II - Jedi Master 13
    Motorola Xoom - WiFi - Rooted - EOS 4.2.1 Nightlies

  5. #4
    Rescue Squad

    Member #
    608
    Join Date
    Mar 2011
    Location
    EARTH
    Posts
    14,422
    Liked
    294 times
    yeah uac in windows was supposed to solve that in windows to lmao.
    <img src=http://www.xoomforums.com/forum/signaturepics/sigpic608_2.gif border=0 alt= />
    Never Fear the iOwl is Here


 

Ads

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts

Similar Threads

  1. Android bug lets attackers install malware without warning
    By ggrant3876 in forum Off-Topic Forum
    Replies: 1
    Last Post: 09-28-2011, 04:43 PM
  2. Replies: 0
    Last Post: 09-10-2011, 07:56 PM
  3. Android malware masquerading as Google+ app
    By ggrant3876 in forum Off-Topic Forum
    Replies: 13
    Last Post: 08-25-2011, 11:21 AM
  4. Newest Android Malware Allows Hackers to Control Your Phone
    By dgstorm in forum Motorola Xoom News
    Replies: 6
    Last Post: 06-08-2011, 12:34 PM
  5. Scary Android Malware Quickly Pulled From Market
    By wicked in forum Motorola Xoom News
    Replies: 8
    Last Post: 03-02-2011, 07:47 AM

Search tags for this page

motorola xoom

Click on a term to search for related topics.