Kaspersky warns phone users of PC-infecting malware

Feb 05, 2013 by Nancy Owano report
Credit: Kaspersky Lab

(Phys.org)—Kaspersky Lab has a new warning for smartphone and tablet users. Yes, it's all about Android. No, it's not like anything you've been warned about before. Lab Expert Victor Chebyshev has discovered a new attack vector in the form of nasty apps (DroidCleaner and Superclean) posing as system cleaners for freeing up memory, and boosting performance by cleaning out old data. The apps are malware. The Superclean and DroidCleaner are the apps that transfer malware. Instead of just infecting the phone they are designed to move across, infecting both the smartphone and PC.

The malware capabilities include stealing data from the victim's and PC as well as eavesdropping on conversations. Kaspersky Lab said the malware was the most extensive feature set it had seen in one .

After plugging an Android device into a , the action starts. The H ran a discussion of how the malware operates: "The app moves on to quietly download three files and save them as "autorun.inf", "folder.ico" and "svchosts.exe" in the root directory of the SD card. Now the phone is ready to infect any PC that it is plugged into when in USB drive emulation mode – if, of course, it still autoruns removable media, and will trigger the running of "svchosts.exe".

The Android version of the bot includes the following features: sending SMS messages; uploading SMS messages; deleting SMS messages; enabling Wi-Fi; opening arbitrary links in a browser; uploading the 's contents; uploading an arbitrary file (or folder) to the master's server; uploading contacts/photos/coordinates from device to master.

The good news for all this is that current versions of Windows pose no such risk. The attack did depend on the AutoRun feature being enabled in Windows for external drives. The current versions have AutoRun disabled. The attack is only possible against users running older unpatched versions of the OS.

Still, news of the discovery by Kaspersky Lab that the apps were on Google Play, where they are no longer, seemed to have an unsettling effect on most technology sites that carried the news. Though the cleaner-masquerading apps no longer reside in Google Play, the idea that they were sitting there for any length of time was reminder enough that mobile phone users need to think twice about what they download and install.

Explore further: Researchers develop new program to evaluate prominent individuals' personalities

More information: www.securelist.com/en/blog/805/Mobile_attacks

Related Stories

Google puts malware scanner in Google Play pipeline

Oct 16, 2012

(Phys.org)—A new version of the Google Play app store will enable scanning users' smartphones for malware, according to Android Police. The site's report, headlined "A Built-In Malware Scanner," said, ...

Recommended for you

Watching others play video games is the new spectator sport

Aug 29, 2014

As the UK's largest gaming festival, Insomnia, wrapped up its latest event on August 25, I watched a short piece of BBC Breakfast news reporting from the festival. The reporter and some of the interviewees appeared baff ...

SHORE facial analysis spots emotions on Google Glass

Aug 28, 2014

One of the key concerns about facial recognition software has been over privacy. The very idea of having tracking mechanisms as part of an Internet-connected wearable would be likely to upset many privacy ...

User comments : 1

Adjust slider to filter visible comments by rank

Display comments: newest first

frajo
5 / 5 (1) Feb 05, 2013
The good news for all this is that current versions of Windows pose no such risk.

The good news for all is that former and current versions of Linux and eCS never posed such risk.