Trend Micro Facebook TrendLabs Twitter Malware Blog RSS Feed You Tube - Trend Micro
Search our blog:

  • Recent Posts

  • Calendar

    May 2012
    S M T W T F S
    « Apr    
     12345
    6789101112
    13141516171819
    20212223242526
    2728293031  
  • About Us
    Malware Blog > Android Malware Eavesdrops on Users, Uses Google+ as Disguise

    Last week, we reported on ANDROIDOS_NICKISPY.A and ANDROIDOS_NICKISPY.B, Android malware that recorded phone calls made from infected devices then sent stolen information to a remote site.

    This week, we saw another Android malware with the same code structure as ANDROIDOS_NICKISPY.A. Like the latter, this does not display an icon and executes similar routines, save for some modifications.

    Detected by Trend Micro products as ANDROIDOS_NICKISPY.C, it uses the following services:

    • MainService
    • AlarmService
    • SocketService
    • GpsService
    • CallRecordService
    • CallLogService
    • UploadService
    • SmsService
    • ContactService
    • SmsControllerService
    • CommandExecutorService
    • RegisterService
    • CallsListenerService
    • KeyguardLockService
    • ScreenService
    • ManualLocalService
    • SyncContactService
    • LocationService
    • EnvRecordService

    This malware comes in the guise of Google+, Google’s most recent foray into the social networking scene, in an attempt to hide from affected users. All the above-mentioned services use the Google+ icon. The app itself is installed using the name, Google++.

    Click for larger view Click for larger view

    ANDROIDOS_NICKISPY.C is capable of collecting data such as text messages, call logs, and GPS location from infected devices, which it then uploads to a certain URL through port 2018.

    It is also capable of receiving commands via text messages. To do so, however, it requires the sender to use the predefined “controller” number from the malware’s configuration file to send a message as well as to enter a password to execute the command.

    Listening In

    Like other ANDROIDOS_NICKISPY variants, ANDROIDOS_NICKISPY.C also has the capability to record phone calls made from infected devices. What makes this particular variant different is that it has the capability to automatically answer incoming calls.

    Click for larger view

    The code suggests that the following criteria must be met before the malware can answer a phone call:

    1. The call must come from the number on the “controller” tag from its configuration file.
    2. The phone screen must be turned off.

    Before answering the call, it puts the phone on silent mode to prevent the affected user from hearing it. It also hides the dial pad and sets the current screen to display the home page. During testing, after the malware answered the phone, the screen went blank.

    Click for larger view Click for larger view

    From the looks of it, the developer of this app went for the more real-time kind of eavesdropping as well, apart from the one ANDROIDOS_NICKISPY.A used, which involved recording calls.

    The “auto-answering” function of this malicious Android app works only on Android 2.2 and below since the MODIFY_PHONE_STATE permission was disabled in Android 2.3.

    For ways to keep your Android-based devices secure, check out our e-book, “5 Simple Steps to Secure Your Android-Based Smartphones.”

    Additional analysis by Julius Dizon and Kervin Alintanahin

    Related blog entries here:





    Share this article
    Get the latest on malware protection from TrendLabs
    Email this story to a friend   Technorati   NewsVine   MySpace   Google   Live   del.icio.us   StumbleUpon




    88 Responses to “Android Malware Eavesdrops on Users, Uses Google+ as Disguise”

    Trackbacks

    1. New Android Spyware Threat Disguises Itself as Google+ App | Teknik Enshus
    2. New Android Spyware Threat Disguises Itself as Google+ App | Tmobile News
    3. New Android Spyware Threat Disguises Itself as Google+ App | Android Blog
    4. New Android Spyware Threat Disguises Itself as Google+ App | galaxytb.com
    5. New Android Spyware Threat Disguises Itself as Google+ App | Hottest Gadget
    6. New Android Malware Hides as Google+ App, Answers Calls for You | Droid Universe
    7. iPhone Games » New Android Malware Hides as Google+ App, Answers Calls for You
    8. New Android Spyware Threat Disguises Itself as Google+ App | Electronic Gadgets
    9. TrendMicro Malware Blog August 15, 2011
    10. New Android Malware Hides as Google+ App, Answers Calls for You | TechDiem.com
    11. New Android Malware Hides as Google+ App, Answers Calls for You | Android News Center
    12. Nuevo Malware oculto en una App para Google+. | HosterBlog
    13. New Android Malware Hides as Google+ App, Answers Calls for You | Krantenkoppen Tech
    14. Android Malware Records Calls, Masks as Google+
    15. Android Malware Records Calls, Masks as Google+
    16. Malware que se disfarça de Google+ » Shelter-Tech
    17. New Android Malware Hides as Google+ App, Answers Calls for You | Android Tablets News
    18. New Android Spyware Threat Disguises Itself as Google+ App | Gadget Information
    19. New Android Malware Hides as Google+ App, Answers Calls for You | Market To Phones
    20. New Android Malware Hides as Google+ App, Answers Calls for You
    21. New Android Malware Hides as Google+ App, Answers Requires You | Modern Techie
    22. New Android Spyware Threat Disguises Itself as Google+ App | Techost.info
    23. New Android Malware Disguises Itself As Google+, Records Phone Calls, Call Logs And Text Messages | Redmond Pie
    24. Android Malware Disguised as Google+ App | Hubze Blog
    25. New Android Malware Hides as Google+ App, Answers Calls for You | iMobile One
    26. New Android Malware Hides as Google+ App, Answers Calls for You | Bitmag
    27. New Android Spyware Threat Disguises Itself as Google+ App - Latest Info & News
    28. Web and Technology » Blog Archive » New Android Spyware Threat Disguises Itself as Google+ App
    29. New Android Spyware Threat Disguises Itself as Google+ App | Gadget News Site
    30. New Android Spyware Threat Disguises Itself as Google+ App - Frenmobile.info
    31. New Android Malware Hides as Google+ App, Answers Calls for You « Whella : All About Mobile
    32. New Android Spyware Threat Disguises Itself as Google+ App | End User Personal Desktop
    33. New Android Spyware Threat Disguises Itself as Google+ App | All around Gadget
    34. New Android Spyware Threat Disguises Itself as Google+ App | Agregatenews.info
    35. New Android Spyware Threat Disguises Itself as Google+ App | Latest Gadgets News
    36. New Android Spyware Threat Disguises Itself as Google+ App | Simplyhotnews.info
    37. Android malware answers calls, eavesdrops on users | RXTX
    38. New Android Spyware Threat Disguises Itself as Google+ App | Gadget Geek Gifts
    39. Malware ตัวใหม่ของ Android แอบอยู่ในแอพ Google+
    40. New Android Malware Hides as Google+ App, Answers Calls for You | Push to Talk
    41. New Android Malware Disguises Itself As Google+, Records Phone Calls, Call Logs And Text Messages
    42. 一个新Andr​​oid恶意软件:伪装成Google+ App | 牛牛网
    43. Android 竊聽風雲 | PK Information Security
    44. New Android Malware Disguises Itself As Google+, Records Phone Calls, Call Logs And Text Messages | iPhone5 news, updates, articles, apps
    45. מתחזים לגוגל פלוס | Newsgeek
    46. New Android Malware Hides as Google+ App, Answers Calls for You | Product Launch Buzz
    47. Android malware answers calls, eavesdrops on users | Just Got Hacked
    48. Google++ ismi ile gizlenen Malware Aramaları ve Mesajları kayıt ediyor - SiberElma
    49. New Android Malware Hides as Google+ App, Answers Calls for You » FaceiZ
    50. New Android Malware Hides as Google+ App, Answers Calls for You | 0code.net - Sharing Everything
    51. Detectado nuevo troyano en Android capaz de responder a las llamadas | eWEEK Europe España
    52. New Android Malware Disguises Itself As Google+, Records Phone Calls, Call Logs And Text Messages | Wherz It At Today
    53. Android malware masquerading as Google+ app | News Channel – Mind Processors
    54. Android malware masquerading as Google+ app | I Bleed Bits | Android
    55. Android malware masquerading as Google+ app | Android News Center
    56. Android malware masquerading as Google+ app | Android Tablets News
    57. Android malware masquerading as Google+ app
    58. Drošības Eksperti
    59. Alertan de un troyano para Android que contesta a las llamadas - Foros de Informatica - Foro de Windows 7, Foro de ayuda, Noticias de Informatica, Windows 7 y Windows Vista
    60. Android malware masquerading as Google+ app | Andriod
    61. Android malware masquerading as Google+ app | Android Blog
    62. Android malware masquerading as Google+ app - Tech News
    63. Android malware masquerading as Google+ app | BestXperiaPlay.com
    64. Zepley – Android malware hiding as Google+ app discovered
    65. Android malware masquerading as Google+ app | RegionalForward.info
    66. Android malware masquerading as Google+ app | RegionalForward.info
    67. Android malware masquerading as Google+ app | IT News Post
    68. ADROIDOS_NICKISPY.C, un troyano sin parangón
    69. Android malware masquerading as Google+ app | Source Of Drivers
    70. New Android malware disguises itself as Google+ App | Latest Telecom Technology News and Updates
    71. Alertan de un troyano para Android que contesta a las llamadas | The Inquirer ES
    72. Android users will have to deal with yet another blow,new Android Malware disguises itself as Google+ - Xponent 4
    73. Google++ : Attention danger pour Android - Android-Zone.fr | Android-Zone.fr
    74. Malware en Android que puede confundirse con la aplicación de Google+ | GeeksRoom
    75. Malware en Android que puede confundirse con la aplicación de Google+ | Tecnologia, Desarrollo Web, Posicionamiento Web SEO
    76. Fake App Is Fake: Google++ Hides A Trojan Inside.
    77. CodeAndroid Thailand : Android Developer and User Group in Thailand » Blog Archive » Trend Micro ออกมาเตือนให้ระวังแอพฯมัลแวร์ Google++
    78. New Android Malware Hides as Google+ App, Answers Calls for You | AndroidFools
    79. Spying Android Malware Hides as Google+ App | Android Blog
    80. Spying Android Malware Hides as Google+ App | LocatePC | Locate your stolen computer or stolen laptop - Works for both Mac and PC
    81. Novo Malware para Android é Capaz de Atender Chamadas | InvasaoHacking.com - Downloads, Video Aulas e Tutoriais sobre Hacker, Trojans, Keyloggers, Worms, Malwares, Virus, phishing, Exploit, Shells, Defacer, banking, carding, Hackear orkut, Hackear Msn, H
    82. Malware Masquerades as Google+ App | Inc. Technology
    83. Появи се нов Android спайуер, маскиран като Google+ приложение | Нова.бг
    84. Fraud Consulting Ltd – Android Malware Disguised as Google+
    85. In wake of Android Trojans, enterprises need Android security policy | Android Tablets
    86. In wake of Android Trojans, enterprises need Android security policy | Android
    87. Android Malware Eavesdrops on Users, Uses Google+ as Disguise | Simply Security
    88. ¡Cuidado! Hay un nuevo virus en Android camuflado de Google+ | soyApps.com


     

    © Copyright 2011 Trend Micro Inc. All rights reserved. Legal Notice