Εντοπισμός Trojan malware στην εφαρμογή CamScanner για Android
Aug 28, 2019
Η γνωστή και δημοφιλής εφαρμογή σάρωσης εγγράφων από κινητό Android CamScanner, βρέθηκε να περιέχει βιβλιοθήκη με κακόβουλο κώδικα (Trojan-Dropper.AndroidOS.Necro.n), από ερευνητές της Kaspersky. Ο εντοπισμός έγινε μετά από αναφορές χρηστών της στο Google Play Store για κακόβουλη λειτουργία της εφαρμογής.
This module — identified as Trojan-Dropper.AndroidOS.Necro.n — is a trojan dropper, meaning it can extract and run a second malicious component encrypted within the app. This trojan downloader can be leveraged to infect the devices with other kinds of malware.
Kaspersky researchers found that when CamScanner is run, the dropper decrypted and executed malicious code contained in a “mutter.zip” file within the app, before downloading encrypted code from a command-and-control server “https://abc.abcdserver[.]com.”
“The above-described Trojan-Dropper.AndroidOS.Necro.n functions carry out the main task of the malware: to download and launch a payload from malicious servers,” the researchers said. “As a result, the owners of the module can use an infected device to their benefit in any way they see fit, from showing the victim intrusive advertising to stealing money from their mobile account by charging paid subscriptions.”
[via]
Labels: Android, Google, Mobile Alert, Mobile phones, News, Security
0 Comments:
Post a Comment