Australian Technology

Update apps, get malware

Takeaway: From the “Wow that’s cool, hope it doesn’t happen to me” files comes news that F-Secure has discovered an Android application that will update itself and install malware known as DroidKungFu.

The technique used is to install an application free of the trojan, then once installed, immediately notify the user that an update is available. This update will ask for additional privileges to access SMS and MMS messages, as well as the location data, and once the user agrees to give access, the trojan is installed.

Once installed on the system, the trojan gains root superuser privileges by using an exploit for Android 2.2.

F-Secure says that DroidKungFu will forward confidential details onto a remote server and is distributed on non-authorised Android app sites as trojanised versions of legitimate applications.

Full details including screenshots are available on F-Secure’s blog.

This is a rather interesting way to get malware onto a device. By updating an already-installed application, the malware makers are hoping that users are much less likely to check permission requests on an update.

The really pertinent part for developers is that F-Secure is unsure whether the original developer intended for their software to be used to distribute malware. F-Secure opines that it is possible that the developer’s back-end has been compromised.

How secure are your mobile deployment servers? Would you know if a third party compromised your APKs?

Get IT Tips, news, and reviews delivered directly to your inbox by subscribing to TechRepublic’s free newsletters.

Chris Duckett

About Chris Duckett

Programmer and journalist Chris Duckett is the Editor for TechRepublic Australia.

Chris Duckett

Chris Duckett
Chris started his journalistic adventure in 2006 as the Editor of Builder AU after originally joining the company as a programmer. He left CBS Interactive in 2010 to follow his deep desire to study the snowdrifts and culinary delights of Canada and returned to CBS in 2011 as the Editor of TechRepublic Australia, determined to meld together his programming and journalistic tendencies once and for all.
3
Comments

Join the conversation!

Follow via:
RSS
Email Alert