Lookout Identifies Advanced Android Trojan (But You're Probably Safe)

Wednesday, December 29th, 2010

Jason Kincaid currently works as a writer at TechCrunch. He grew up in Danville, California and later relocated to UCLA in Los Angeles, California, where he studied biology with a minor in ‘Society and Genetics’. You can reach him at jkincaidtc@gmail.com (he has other addresses too, so don’t worry if you have a different one). → Learn More

The future of computing is mobile, and, unfortunately, the future of malware will probably lie there too. Well-funded mobile security startup Lookout has just posted a blog entry detailing what it calls “the most sophisticated Android malware to date”: a Trojan that’s being “grafted” onto legitimate applications. Fortunately, the odds of you being affected are quite low.

The Trojan in question has only been seen on third-party Android app marketplaces in China, which aren’t accessible without turning on “Unknown Sources” from Android’s settings menu (the vast majority of users only download applications via the official Android Market). And the infected applications request access to far more of the user’s data than they normally would (users have to approve these requests before installing an app), which can tip users off that something is amiss.

But, if you’re unlucky enough to have cleared those hurdles, here are some of the details on what Lookout believes the Trojan is capable of:

Though we have seen Geinimi communicate with a live server and transmit device data, we have yet to observe a fully operational control server sending commands back to the Trojan. Our analysis of Geinimi’s code is ongoing but we have evidence of the following capabilities:

Send location coordinates (fine location)
Send device identifiers (IMEI and IMSI)
Download and prompt the user to install an app
Prompt the user to uninstall an app
Enumerate and send a list of installed apps to the server

Lookout writes that this is more sophisticated than previously discovered malware because it attempts to hide what it’s doing through encryption and bytecode obfuscation. It also says that this is the first Android malware that could potentially be used to create a botnet, though it hasn’t seen any instances of a server actually communicating with the Trojan yet:

Geinimi is also the first Android malware in the wild that displays botnet-like capabilities. Once the malware is installed on a user’s phone, it has the potential to receive commands from a remote server that allow the owner of that server to control the phone.

One other thing to note: Lookout is in the business of mobile phone security — it offers applications for Android, BlackBerry, and Windows mobile — so it obviously stands to benefit from exposing these exploits.

Company: Android
Website: android.com

In August 2005, Google acquired Android, a small startup company based in Palo Alto, CA. Android’s co-founders who went to work at Google included Andy Rubin (co-founder of Danger), Rich Miner (co-founder of Wildfire), Nick Sears (once VP at T-Mobile), and Chris White (one of the first engineers at WebTV). At the time, little was known about the functions of Android other than they made software for mobile phones. This began rumors that Google was planning to enter...

Learn more
Company: Lookout
Website: mylookout.com
Funding: $76M

Lookout provides award-winning security to protect your mobile phone from viruses, malware and spyware, the ability to backup and restore your data, and tools to help locate lost or stolen phones. Lookout’s unique cross-platform, cloud-connected applications are designed to be lightweight and efficient while delivering the best protection possible. Our Mobile Threat Network scans applications worldwide, allowing us to find and stop threats before they ever become a risk to you so you can rest assured that you’re protected...

Learn more

Sponsored Ads

blog comments powered by Disqus

Sponsored Ads

Sponsored Ads

Upcoming Events

SXSW 2012

Austin, Texas

Disrupt NY 2012

New York City

Disrupt SF 2012

San Francisco, CA