All the latest UK technology news, reviews and analysis

DroidDream Android malware contains hidden payload

by Iain Thomson

04 Mar 2011

Be the first to comment

  • Tweet this

A closer analysis of the DroidDream malware found embedded in applications on the Android Market shows a second payload that may cause further security problems.

Kevin Mahaffey, chief technical officer at Lookout, told V3.co.uk that the DroidDream software searches for a specific package named com.android.providers.downloadsmanager.

If this is not present, it installs a second piece of code. Analysis of this second payload is continuing, but could be the underpinnings to create a botnet.

"We're still analysing the application, so I'll draw a line between what we know for sure. So far this code has used an exploit to route the phone and break out of the security sandbox," said Mahaffey.

The initial attack came via two known flaws in the Android operating system, exploid and rageagainstthecage, which have been patched in version 2.3. Initially it sends the IMEI, IMSI, device model and SDK version to a remote command and control server.

The malware was initially spread by three software developers on the Android Market who inserted it into 55 basic applications in a variety of languages. They then submitted applications, inserted the malware and recertified the package for distribution.

The case shows the problems and benefits of an open system from a security standpoint. Android Market's open nature is in contrast to companies like Apple and Amazon, which certify applications and decide what to allow.

However, malware has made it onto Apple's App Store, and Android's open source approach detected the virus quickly.

"A community-enforced model, in this case, was a silver lining," Mahaffey said. "This all came to light because one developer put his hand up and said: 'I found something' because he had the tools to do so."

 

Do you agree?

 

Add your comment

We won't publish your address
By submitting a comment you agree to abide by our Terms & Conditions. Your comment will be moderated before publication.

Poll

Flame virus poll

Are you confident that the UK's IT infrastructure is secure from attack in the wake of the Flame malware revelations?

31%

1%

11%

57%

Connect with V3.co.uk

Sign up to our daily or weekly newsletters

Symanteccloud

Social networking: a guide for IT managers

Social networking is almost ubiquitous. This white paper examines the benefits and risks and it looks at the different ways companies can reconcile them

Riverbed

Mitigating the risks of IT change

The importance of understanding your infrastructure

Systems Engineer

Lead/Project Engineer Microsoft VMware SAN Networking...

Application Tester

SENIOR APPLICATION TESTER. Assen, Netherlands. €1k-€1...

Project Manager - Trading Systems - up to £85'000

Project Manager - Trading Systems - up to £85'000...

SAS Senior Analyst- Direct Marketing Agency

SAS Senior Analyst- up to £55,000 Industry: Marketing...

To send to more than one email address, simply separate each address with a comma.