Kaspersky warns phone users of PC-infecting malware

Feb 05, 2013 by Nancy Owano report
Credit: Kaspersky Lab

(Phys.org)—Kaspersky Lab has a new warning for smartphone and tablet users. Yes, it's all about Android. No, it's not like anything you've been warned about before. Lab Expert Victor Chebyshev has discovered a new attack vector in the form of nasty apps (DroidCleaner and Superclean) posing as system cleaners for freeing up memory, and boosting performance by cleaning out old data. The apps are malware. The Superclean and DroidCleaner are the apps that transfer malware. Instead of just infecting the phone they are designed to move across, infecting both the smartphone and PC.

The malware capabilities include stealing data from the victim's and PC as well as eavesdropping on conversations. Kaspersky Lab said the malware was the most extensive feature set it had seen in one .

After plugging an Android device into a , the action starts. The H ran a discussion of how the malware operates: "The app moves on to quietly download three files and save them as "autorun.inf", "folder.ico" and "svchosts.exe" in the root directory of the SD card. Now the phone is ready to infect any PC that it is plugged into when in USB drive emulation mode – if, of course, it still autoruns removable media, and will trigger the running of "svchosts.exe".

The Android version of the bot includes the following features: sending SMS messages; uploading SMS messages; deleting SMS messages; enabling Wi-Fi; opening arbitrary links in a browser; uploading the 's contents; uploading an arbitrary file (or folder) to the master's server; uploading contacts/photos/coordinates from device to master.

The good news for all this is that current versions of Windows pose no such risk. The attack did depend on the AutoRun feature being enabled in Windows for external drives. The current versions have AutoRun disabled. The attack is only possible against users running older unpatched versions of the OS.

Still, news of the discovery by Kaspersky Lab that the apps were on Google Play, where they are no longer, seemed to have an unsettling effect on most technology sites that carried the news. Though the cleaner-masquerading apps no longer reside in Google Play, the idea that they were sitting there for any length of time was reminder enough that mobile phone users need to think twice about what they download and install.

Explore further: Kaspersky Lab nails 'Find and Call' trojan bearing phone-book service

More information: www.securelist.com/en/blog/805/Mobile_attacks

Related Stories

Google puts malware scanner in Google Play pipeline

Oct 16, 2012

(Phys.org)—A new version of the Google Play app store will enable scanning users' smartphones for malware, according to Android Police. The site's report, headlined "A Built-In Malware Scanner," said, ...

Recommended for you

Model will unlock mysteries of the voice

6 hours ago

Swedish researchers are leading the development of the world's first comprehensive model of the human voice, which could contribute to better voice care, voice prosthetics, talking robots and teaching opportunities.

Patented system better secures digitally stored data

May 21, 2013

(Phys.org) —Arizona State University computer scientist Gail-Joon Ahn has been granted a U.S. patent for a novel identity management system that helps protect personal identity information stored on digital devices.

UC Davis startup changes listening experience

May 20, 2013

Fifteen years of research at the University of California, Davis, is being turned into commercial products by Dysonics, a startup company based in San Francisco. Since becoming the first "graduate" from the Engineering Translational ...

Research finds new channels to trigger mobile malware

May 16, 2013

(Phys.org) —Researchers at the University of Alabama at Birmingham (UAB) have uncovered new hard-to-detect methods that criminals may use to trigger mobile device malware that could eventually lead to targeted ...

User comments : 1

Adjust slider to filter visible comments by rank

Display comments: newest first

frajo
5 / 5 (1) Feb 05, 2013
The good news for all this is that current versions of Windows pose no such risk.

The good news for all is that former and current versions of Linux and eCS never posed such risk.

More news stories

Solar plane aims for new world distance record

Solar Impulse, the first aircraft that can fly day and night fueled entirely by energy from the sun, embarked Wednesday on the second leg of its historic journey across the American continent.

Facebook joins Web freedom group

Facebook on Wednesday became a full member of the Global Network Initiative, a non-governmental organization promoting Internet freedom and privacy rights.