Showing posts with label malware. Show all posts
Showing posts with label malware. Show all posts

Wednesday, July 24, 2013

Android Malware jumps 6 fold in last few months

Well, I don't think this is a surprise to anyone.

Per a report by Alcatel-Lucent's Kindsight Security Labs (you can read it HERE.), Android malware has increased 6 fold to over 120,000.  The bulk of these are Trojans of various sorts (the report gives you a breakout of the top ones).

Yesh.

And, sadly, this also shows the weakness of application signing to weed out the malware.  We've already seen issues with Google's Bouncer keeping out the bad stuff, as well as what BlueBox recently found.  (see my prior posts on both of these matters).

Related, they also show an increase in infected home networks.  Again, not a big surprise if you think about it.  Most people who setup home networks have little or no IT (much less IT Security) background.

For a good overview article, read THIS from Ziff-Davis.

Again, what I see here could be addressed by a couple of things.

1. Obviously Bouncer needs to be improved.  BUT people can't rely upon it solely.
2. People need to be encouraged to install anti-malware apps on their smartphones.  Ideally, just as with most PC that come preinstalled with a commercial AV program (usually with a set period of free use), we need to start seeing smartphones come pre-installed with SOME kind of anti-malware app.  AND those people writing and putting out books/magazines on smartphones need to include security apps as part of their recommended installs people should have on their smartphones.

Monday, June 3, 2013

Android malware disguised as anti-malware software

Something I don't think a lot of security professions are aware of is the trend of users being tricked by fake anti-virus/anti-malware software that is really malware!  (apparently we now have a term for this: scareware)  People are so concerned about getting infected, that they install software they think will protect them, when, in fact, its infecting your system.

A recent presentation I was at said that the largest vector for Macintosh malware is via such fake anti-malware apps.  And, per another article, there is way more fake anti-malware on Windows then on Mac.  Big surprise.

And it shouldn't be a big surprise that the bad guys are doing the same on smartphones as well.

HERE is a great posting at Sophos' Naked Security blog on a deep examination of one such fake anti-malware on the Android platform.  Check it out.  A good read, with some great information.

Wednesday, May 29, 2013

Failure of Bouncer

In a previous posting, I mentioned Bouncer, Google's service within the Google Play Store that is supposed to keep out malware.  This is important, because the Play Store does not vet new apps to the level that Apple's App Store does, meaning that Google Play becomes one of the biggest vectors for malware to get into Android phones.


Well, per a recent article at ArsTechnica, someone figured out how to get around this.  I discovered this thru an article at TechRepublic.

Apparently how they did it was upload an app to Google that was ok, which was checked by Bouncer.  Then they uploaded a new version of that app, this one with the malware.  Now, I have to wonder why Bouncer didn't re-check it.  Wouldn't that malware app be different (different size, atleast a new update date), and thus Bouncer would re-examine it?  Seems its not setup that way.  Certainly a new upload, if its not a new size, should trigger a recheck.

Apparently some 9 million user got it.  Upsy.

Check out the article at TechRepublic.  I thought it had some pretty good points, similar to what I've been saying, on the need for better security stance when it comes to Android.  A big part is that we need to get more people to install AV software (ok, they are really anti-malware, but still) on their phones.  Stop giving people the impression these devices are totally secure, and take practical security in mind.