DroidForums.net is the original Verizon Android Forum! Registered Users do not see these ads. Please Register - It's Free!
Results 1 to 5 of 5

Thread: The Bearer of BadNews

  1. Super Mod/News Team
    Shadez's Avatar
    Member #
    32075
    Join Date
    Jan 2010
    Location
    Lafayette Hill, Pa
    Posts
    8,223
    Liked
    594 times
    Twitter
    @Shadez69
    Phone
    Droid,Droid Bionic/Galaxy SIII
    Premium Member
    #1

    The Bearer of BadNews

    Lookout Malware Warning For Certain Apps!



    Some bad news for some Android Apps. The following is a message from Lookout.

    The Lookout Blog



    April 19, 2013

    Lookout has discovered BadNews, a new malware family, in 32 apps across four different developer accounts in Google Play. According to Google Play statistics, the combined affected applications have been downloaded between 2,000,000 – 9,000,000 times. We notified Google and they promptly removed all apps and suspended the associated developer accounts pending further investigation. All Lookout users are protected against this threat.


    BadNews masquerades as an innocent, if somewhat aggressive advertising network. This is one of the first times that we’ve seen a malicious distribution network clearly posing as an ad network. Because it’s challenging to get malicious bad code into Google play, the authors of Badnews created a malicious advertising network, as a front, that would push malware out to infected devices at a later date in order to pass the app scrutiny.


    Badnews has the ability to send fake news messages, prompt users to install applications and sends sensitive information such as the phone number and device ID to its Command and Control (C&C) server. BadNews uses its ability to display fake news messages in order to push out other types of monetization malware and promote affiliated apps.


    During our investigation we caught BadNews pushing AlphaSMS, well known premium rate SMS fraud malware, to infected devices.


    BadNews is a significant development in the evolution of mobile malware because it has achieved very wide distribution by using a server to delay its behavior. If an app has not yet engaged in malicious behavior, a typical app vetting process would of course conclude that it was safe because the malicious behavior has not yet occurred. We have two big takeaways from the appearance of BadNews:

    1. Developers need to pay very close attention to any third-party libraries they include in their applications. Unsafe libraries can put their users and reputation at risk.
    2. Enterprise security managers must assume that even very well designed app-vetting processes will not be able to detect malicious behavior that hasn’t happened yet. Ongoing security monitoring is important to detect malicious behavior that happens some time after an app’s initial evaluation.

    Impact
    About 50% of the identified applications are in Russian and AlphaSMS is designed to commit premium rate SMS fraud in the Russian Federation and neighboring countries such as the Ukraine, Belarus, Armenia and Kazakhstan. It’s worth noting that the people controlling this malware are also using it promote their less popular apps, which also contain BadNews.




    The following table provides information about each of the 32 identified malicious apps, including high and low download boundaries.




    Lookout’s Take

    BadNews is spun to look like an ordinary advertising network SDK and is hosted in a number of innocuous applications that range from Russian dictionary apps to popular games. It distributes the exact same malware that we have observed across a number of shady affiliate-based marketing websites. In addition, we found BadNews promoting other less popular affiliated apps, including a Russian diet app which also contained the BadNews.

    It is not clear whether some or all of these apps were launched with the explicit intent of hosting BadNews or whether legitimate developers were duped into installing a malicious advertising network. However, based on our analysis of the backend code behind a number of these purported ad networks there is little doubt that BadNews is a fraudulent monetization SDK.

    How it Works

    Once activated, BadNews polls its C&C server every four hours for new instructions while pushing several pieces of sensitive information including the device’s phone number and its serial number (IMEI) up to the server.

    The C&C server replies with instructions telling BadNews what to do next. Available instructions include displaying (fake) news to users, and prompting for installation of a downloaded app payload.

    An example of a “news” response is shown below:


    The Russian text roughly translates to “Critical Update to Vkontakte,” implying an available update to a popular Russian Social Networking app. We have also observed available “update” prompts for Skype.


    In each case, the URL points to a download for the prolific AlphaSMS toll fraud app, which purports to install freely available software, but actually results in fraudulent charges via Premium SMS.


    We have enumerated the majority of available download URLs and determined that most endpoints lead to the download of AlphaSMS. Others lead to cross-promotion of other infected apps on Google Play.


    The APKs themselves have names such as skype_installer.apk, mail.apk, and vkontakte_installer.apk in an attempt to trick the user into accepting the permissions requested during APK installation and also line up with the text in the news article about this being part of a critical update.


    Further, it is clear that a substantial amount of code in BadNews has previously appeared in other families associated with Eastern European toll fraud. The figure below summarizes the similarity of package structure, class names, method names and variables between BadNews and RuPaidMarket.m.






    Command & Control Servers
    We have identified three C&C servers, one in Russia, one in the Ukraine, and one in Germany. All C&C servers are currently live but Lookout is working to bring them down.


    How to Stay Safe

    • Make sure the Android system setting ‘Unknown sources’ is unchecked to prevent dropped or drive-by-download app installs.
    • Download a mobile security app like Lookout’s app that protects against malware as a first line of defense.

    Looking for more information on mobile threats like BadNews? Check out Lookout’s Top Threats resource.

    April 16, 2013

    Via: https://blog.lookout.com/
    Last edited by Shadez; 04-20-2013 at 03:18 AM.
  2.  
     
     
     
  3. Super Mod/News Team
    Shadez's Avatar
    Member #
    32075
    Join Date
    Jan 2010
    Location
    Lafayette Hill, Pa
    Posts
    8,223
    Liked
    594 times
    Twitter
    @Shadez69
    Phone
    Droid,Droid Bionic/Galaxy SIII
    Premium Member
    #2
    Ok I admit it, I had the candle... :/
  4. Droid Ninja
    xeene's Avatar
    Member #
    82269
    Join Date
    Jun 2010
    Location
    usa
    Posts
    1,540
    Liked
    234 times
    Phone
    droid maxx
    #3
    there are so many scams and shams going on in russia/former soviet republics, this is just a tiny tip of an iceberg.
    Sony CM-B1201 > Samsung SCH-8500 > Motorola RAZR V3m > Samsung SCH-i760 > Motorola DROID X > HTC Thunderbolt > Samsung Galaxy Nexus/Motorola Droid Razr Maxx > Droid Maxx
  5. Premium Member
    xtor's Avatar
    Member #
    241487
    Join Date
    Dec 2011
    Location
    Northern Ca
    Posts
    1,280
    Liked
    130 times
    Phone
    note 2
    Premium Member
    #4
    Nice, nothing like scam in you own people

    razr on 215 leak
  6. Master Droid
    comk4ver's Avatar
    Member #
    94035
    Join Date
    Jul 2010
    Posts
    605
    Liked
    20 times
    Phone
    Moto X... The Game?
    #5
    I'm sure that they got to some Americans with their Russian Dictionary.

Links

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •  

Search tags for this page

32 badnews apps

Click on a term to search our site for related topics.
Find us on Google+