Mobile & Gadgets

Top Five Threats to Android Devices

Hijacked applications rogue, power-saving patches and pirated versions of popular commercial software for Android account for the vast majority of security incidents, Bitdefender analysis reveals

In the fast-moving smartphone industry, it took mobile phone manufacturers a little more than 10 years to transform brick-like mobile creations into the current state-of-the-art pieces. On the other side of the fence, the bad guys are ramping up production of mobile malware to squeeze as much as possible from the rapidly growing segment.

The following breakdown is based on a three-month analysis of Android e-threats identified in the Bitdefender antimalware labs and covers the most important five security risks for Android OS users.

The distribution chart of the top Android theats in November 2011:

Although attacks on smartphones have intensified and diversified, the dialers – one of the first threats to target the mobile world – rank highest in the Android infections top, with a total of 36.59%. Also known as premium-rate SMS senders, these dialers are a combination of computer malware and traditional phone con. As a rule, the malicious code takes the guise of legitimate applications or a pirated version of a popular legitimate one to trick the users into downloading and installing them on their smartphones. They mainly end up sending SMSs to premium rate numbers, mostly in Russia.

Another widespread approach is the “private information stealer”. With this spy tool, crooks retrieve details from users’ smartphones about both the phones and their users, including GPS coordinates, contact lists, e-mail addresses, uploaded data etc. The malicious code becomes more complex and the perpetrators’ interest shifts from pranks and “snooping on the girlfriend apps” to proper spying tools with wider repercussions. This could end in, say, theft of company’s a sensitive data through an employee.

And now let’s look at the first five Android malware hits individually:

Android.Trojan.FakeInst – 36.59 %

Pretending to be an installer of applications such as browsers, antiviruses or instant messengers for mobiles, Android.Trojan.FakeInst shakes good money out of the user. Once the user downloads and installs the app, the Trojan starts sending several SMSs to premium-rate numbers. Some samples need confirmation from the user whereas others don’t. Noteworthy is that this Trojan changes its icon regularly to prevent users from spotting down, while carrying the same configuration file with a link toward the app to be installed. And to further trick users into believing they deal with different applications, Android.Trojan.FakeInst inserts an image several times to modify the file size.

Android.Adware.Mobsqueeze – 5.66%

Posing as a power-saving patch, with catchy names such as Battery Doctor or Battery Upgrade, Android.Adware.Mobsqueezeis a piece of adware with spy capabilities. It employs the same tactics as the ill-fated Rogue AV on PCs, namely, it advertises a method of boosting battery life to trick people into downloading it. It turns out to be a spying tool that calls the advertising server and siphons out information about the device and its owner.

Android.Spyware.SMSReplicator – 1.75%

This application secretly forwards to a predetermined phone number all SMS messages on the victim’s phone. It has no icon, which makes it difficult to detect and the application’s window only pops up as soon as the attacker sends the compromised phone an SMS with a special password as text. The same SMS trick with a password as message body is used for its activation and configuration, which outlines the backdoor component in this app.

Android.Trojan.FakePlayer – 1.65%

Android.Trojan.FakePlayer passes itself off as a video player application. However, once installed, it silently sends premium-rate SMS messages worth $5 to Russian phone numbers without requiring confirmation or interaction from the smartphone owner. During installation, the rogue app lays the ground by asking for permission to change or delete the memory card, send SMS or access data about the device or phone owner which will come in handy once it starts the malicious work.

Android.Trojan.Walkinwat – 1.00%

Android.Trojan.Walkinwat claims to be a pirated version of a known application, whereas it acts as a spy sending IMEI, additional phone data, contact names and the associated phone numbers to a remote server.  According to Android.Trojan.Walkinwat specifications, the Trojan could also initiate calls without using the phone’s interface, to turn the phone on and off, or to open network sockets to access the Internet. Meanwhile, it sends SMSs to all contacts in the phone.

This article is based on the technical information provided courtesy of Vlad Constantin ILIE, BitDefender Malware Researcher.

All product and company names mentioned herein are for identification purposes only and are the property of, and may be trademarks of, their respective owners.

About the author

Loredana BOTEZATU

A blend of teacher and technical journalist with a pinch of e-threat analysis, Loredana Botezatu writes mostly about malware and spam. She believes that most errors happen between the keyboard and the chair. Loredana has been writing about the IT world and e-security for well over five years and has made a personal goal out of educating computer users about the ins and outs of the cybercrime ecosystem.

Add Comment

Click here to post a comment

This site uses Akismet to reduce spam. Learn how your comment data is processed.