10 Mar 2011
Malware writers have injected code into repackaged versions of a recent Google Android security fix.
Researchers at Symantec spotted a third-party Chinese marketplace site which is believed to be distributing a version of the Google Android malware fix laced with "suspicious" code.
The application presents itself as a malware fix distributed by Google earlier this week. The 'killswitch' fix addresses a recently detected pack of over 50 malware-infected applications that briefly made their way onto the Android Market.
The fix was automatically distributed to affected users and the official software from Google does not contain any malicious or potentially harmful code.
The repackaged and infected third-party software, however, contains code that could possibly cause Android devices to connect with a command-and-control server.
"Analysis of the application is still ongoing. However, what is shocking is that the threat's code seems to be based on a project hosted on Google Code and licensed under the Apache Licence," Symantec researcher Mario Ballando wrote in a blog posting.
A Google spokesperson told V3.co.uk that users should always obtain Android updates directly from known and trusted sources.
Latest stories from Security
Related videos
Related articles
Related jobs
Poll
Are you confident that the UK's IT infrastructure is secure from attack in the wake of the Flame malware revelations?
Orange and Intel talk us through the ins and outs of their San Diego smartphone
Connect with V3.co.uk
Social networking is almost ubiquitous. This white paper examines the benefits and risks and it looks at the different ways companies can reconcile them
The importance of understanding your infrastructure
Development Manager / PHP Developer / MySQL / LAMP...
Process Expert for Information/Content Management...
SQL Server / SSIS / ETL / T-SQL Data Migration A...
Linux Systems Administrator / Linux CentOS / Network...
Keep up to date with the latest products, services and technologies from the world's leading IT companies. IThound.com brings you over 2,000 white papers, case studies and analyst reports.
Do you agree?
All Google software is malware
Everything that Google produces is designed to spy on its users for Google. Just because Google is the only beneficiary does not make it any less malware.
Posted by: jorjitop 13 Mar 2011