Security News > 2021 > April > Another supply-chain attack? Android maker Gigaset injects malware into victims' phones via poisoned update

Another supply-chain attack? Android maker Gigaset injects malware into victims' phones via poisoned update
2021-04-07 20:11

Roid smartphones from Gigaset have been infected by malware direct from the manufacturer in what appears to be a supply-chain attack.

The Trojan, once downloaded and installed on a victim's device via a poisoned software update from the vendor, is capable of opening browser windows, fetching more malicious apps, and sending people text messages to further spread the malware, say researchers and users.

Gigaset told the news website the incident only affects "Older devices," and that it would provide more details soon.

The antivirus biz identified two of the malware strains emanating from Gigaset as Android/Trojan.

The attack vector is a system update application, identified as com.

Malwarebytes' Nathan Collier speculated in a post that crooks had compromised Gigaset's update servers to distribute the Trojans, a scenario Heise's reporting - and this Google support thread - tends to confirm.


News URL

https://go.theregister.com/feed/www.theregister.com/2021/04/07/gigaset_supply_chain_malware_android_phones/

Related vendor

VENDOR LAST 12M #/PRODUCTS LOW MEDIUM HIGH CRITICAL TOTAL VULNS
Android 4 0 17 2 0 19