Security News

LokiBot Redux Attacks Massive List of Common Android Apps
2020-07-16 07:00

Researchers have discovered a new variant of the LokiBot trojan called BlackRock, that's attacking not just financial and banking apps, but also a massive list of well-known and commonly used brand-name apps on Android devices. While BlackRock's banker abilities are not overly impressive, offering "a quite common set of capabilities compared to average Android banking trojans," according to the report, it has other assets.

Researchers Find Pre-Installed Malware on More Android Phones in U.S.
2020-07-09 18:39

Following a January report on malware found pre-installed on smartphones sold in the United States to budget-conscious users, Malwarebytes has discovered another mobile device riddled with malware from the get-go. Now, Malwarebytes's Nathan Collier says that another phone model provided through the Lifeline Assistance program was found to include pre-installed malware: the ANS UL40 running Android 7.1.1.

Joker Android Malware Dupes Its Way Back Onto Google Play
2020-07-09 16:50

A new variant of the infamous Joker malware has once again made it onto Google Play, with Google removing 11 malicious Android applications from its official app marketplace, researchers disclosed Thursday. "The Joker malware is tricky to detect, despite Google's investment in adding Play Store protections. Although Google removed the malicious apps from the Play Store, we can fully expect Joker to adapt again. Everyone should take the time to understand what Joker is and how it hurts everyday people."

Joker billing fraud malware eluded Google Play security to infect Android devices
2020-07-09 14:36

Always a thorn in Google's side, the Joker malware arrived as a new variant a few months ago and evaded Google Play Protect to infect legitimate apps and sign people up to premium services. Check Point researchers disclosed its findings to Google, which removed 11 identified apps from Google Play by April 30, 2020.

‘Undeletable’ Malware Shows Up in Yet Another Android Device
2020-07-09 13:23

Security researchers have identified yet another Android-based mobile device available through the government-funded Lifeline Assistance Program pre-loaded with malware, a discovery adding evidence to the disturbing trend of smartphones infected with undeletable malicious code upon purchase. Hard on the heels of research exposing the prevalence of pre-installed adware on Android devices, researchers at Malwarebytes Labs found an American Network Solutions UL40 device running Android OS 7.1.1, preloaded with compromised Settings and Wireless Update apps.

Google Patches Critical Android Vulnerabilities With July 2020 Updates
2020-07-08 18:42

Several critical remote code execution vulnerabilities were addressed in Android this week with the release of the July 2020 set of security patches, including three in the media framework and system components. Google addressed two critical flaws in the system component, one impacting Android 8.0 and newer releases, and the other affecting Android 10 only.

Android Users Hit with ‘Undeletable’ Adware
2020-07-06 20:10

UPDATE. A healthy percentage of Android users targeted by mobile malware or mobile adware last year suffered a system partition infection, making the malicious files virtually undeletable. "A system partition infection entails a high level of risk for the users of infected devices, as a security solution cannot access the system directories, meaning it cannot remove the malicious files," the firm explained, in a posting on Monday.

Chinese Hackers Target Uyghurs With Multiple Android Surveillance Tools
2020-07-02 14:31

For seven years, a Chinese threat actor has targeted the Uyghur ethnic minority with several malware families, including newly identified Android surveillance tools, mobile security firm Lookout reports. Malicious attacks focusing on Uyghurs are not new, with several of them publicly detailed over the years, targeting users of Windows PCs, Macs, and mobile devices.

FakeSpy Android Malware Spread Via ‘Postal-Service’ Apps
2020-07-02 13:18

Roid mobile device users are being targeted in a new SMS phishing campaign that's spreading the FakeSpy infostealer. One example of a message used in the latest FakeSpy campaign is an alert from the postal service local to the region of the victim, informing them that the service tried to send a package, but the receiver was not at home, for instance.

Google Details Memory-Related Security Improvements in Android 11
2020-07-01 16:33

Google this week shared details on how it is fighting memory bugs in Android 11, as well as on other security improvements that the upcoming platform version will deliver. One of the main improvements in the new operating system iteration is related to initialization of memory, which is expected to eliminate an entire class of issues that occur in C/C++: uninitialized memory bugs.