Security News > 2021 > November > Android has its head in the sand with AbstractEmu malware rooting phones

A new and dangerous form of malware for rooting Android phones has been spotted in 19 apps on Google's Play store, as well as in several in the Amazon Appstore, the Samsung Galaxy Store, and other third-party sites.
Dubbed AbstractEmu by bug-hunters at Lookout, who first spotted the code, the malware would give full access to all functions on an Android device and would be almost impossible to remove without doing a full system wipe.
Hive ransomware targets Linux and FreeBSD. The criminals behind the Hive ransomware strain have apparently widened their ambitions and are now targeting open-source systems.
Security shop ESET reported that the ransomware is now available in Linux and FreeBSD flavours, which represents a widening of targets, as the gang previously just went for Windows operating systems.
Luckily the new variant appears to be in a development phase and isn't particularly well written, often failing to encrypt targeted systems.
It supports only one command line parameter, compared to five for Windows systems, and requires full root access to work.
News URL
https://go.theregister.com/feed/www.theregister.com/2021/11/01/in_brief_security/
Related news
- Triada Malware Preloaded on Counterfeit Android Phones Infects 2,600+ Devices (source)
- SpyLend Android malware downloaded 100,000 times from Google Play (source)
- Vo1d malware botnet grows to 1.6 million Android TVs worldwide (source)
- Serbian police used Cellebrite zero-day hack to unlock Android phones (source)
- Amnesty Finds Cellebrite’s Zero-Day Used to Unlock Serbian Activist’s Android Phone (source)
- BadBox malware disrupted on 500K infected Android devices (source)
- North Korea’s ScarCruft Deploys KoSpy Malware, Spying on Android Users via Fake Utility Apps (source)
- New Android malware uses Microsoft’s .NET MAUI to evade detection (source)
- APT36 Spoofs India Post Website to Infect Windows and Android Users with Malware (source)
- Android Malware Exploits a Microsoft-Related Security Blind Spot to Avoid Detection (source)