Pre-loaded Malware Found On TECNO Smartphones:
The Deathring Trojan
When you walk out of a retailer with a shiny new
phone, you trust that it’s clean and safe to use. But
this might not always be the case, as evidenced by the
latest pre-loaded malware Lookout identified called
" DeathRing ". DeathRing is a Chinese Trojan that is
pre-installed on a number of smartphones most
popular in Asian and African countries.
The Trojan masquerades as a ringtone app, but
instead can download SMS and WAP content from
its command and control server to the victim’s
phone. It can then use this content for malicious
means. For example, DeathRing might use SMS content
to phish victim’s personal information by fake text
messages requesting the desired data. It may also use
WAP, or browser, content to prompt victims to
download further APKs — concerning given that the
malware authors could be tricking people into
downloading further malware that extends the
adversary’s reach into the victim’s device and data.
The malware is activated in two ways — both
dependent on the victim’s use of the phone. First, the
malware will activate if the phone is powered down
and rebooted five times. On the fifth reboot, the
malware starts. Second, the malicious service will start
after the victim has been away and present at the
device at least fifty times.
Counterfeit Samsung GS4/Note II
Various TECNO devices
Gionee Gpad G1
Gionee GN708W
Gionee GN800
Polytron Rocket S2350
Hi-Tech Amaze Tab
Karbonn TA-FONE A34/A37
Jiayu G4S – Galaxy S4 Clone
Haier H7
No manufacturer specified i9502+ Samsung Clone
The main countries of concern are Vietnam, Indonesia,
India, Nigeria , Taiwan, and China.
Android Tutorial, Android app, Android learning zone, Android problem, Android solution We speak Android
Monday, 8 December 2014
TECNO, Gionee, & Fake Galaxy Phones Preloaded With DeathRing Trojan?
Subscribe to:
Post Comments (Atom)
No comments:
Post a Comment