RAT rootkit for Android

The newest distros the lastest Nvidia driver, gadgets .....

Moderators: b1o, jkerr82508

User avatar
viking60
Über-Berserk
Posts: 9351
Joined: 14 Mar 2010, 16:34

RAT rootkit for Android

Postby viking60 » 10 Mar 2014, 21:53

Image
Symantec has discovered a Remote Access Tool (RAT) for Android phones. This tool makes it easy for bad people to make malicious Android Apps and it is called Dendroid.

If you plan a criminal career it will only cost you $300 to get you started in the black underground market. Then you would get a tool called APK Binder which simply binds your malicious code to any clean APK (Android Application Package).

This will then allow remote access via a control panel in PHP on a server that the makers of Dendroid control - not you - the aspiring criminal.

Now you can enjoy the features; include deleting call logs and files; calling phone numbers; opening Web pages; recording calls and audio from the microphone; intercepting text messages; taking and uploading photos and videos; opening applications and launching HTTP flood (denial-of-service) attacks for a period of time specified by you the attacker.

:think:
It might be the Norwegian PST that is behind this - since they are in the market of keyloggers - and the rest sounds exactly like what the NSA and GCHQ already do - so how can this be illegal?

This malware is actually a cloud service ran by servers. If the servers go down your remote access is gone - and the privacy of the poor victims restored.

So how can you get infected?
Well by downloading your apps from third party app stores. Google's policy prevents this from happening. Another way is by buying a pre-infected phone.

These phones are infected deliberately somewhere in the supply chain.

So the worlds largest Mobile phone system has become a target of this and the anti virus industry is rejoicing. Symantec is overplaying the risk and recommends you to buy Norton Mobile security - which is hardly surprising.

Or you could simply stick to Google Play. The chance of having one crook in the supply chain for a period of time is slim - Samsung and Google will find ways to smoke them out and make rules to avoid this in the future. They have probably done that already.

The third party app stores are very popular in Russia and China - so that is where you will find the most infections.

But then again you could have a heart and buy a Mobile AV from them since business has been extremely slow since Windows 8 has ruined the PC sales.

Windows has been the AV companies best friend - and that era could be over. That is not good news for companies making their living out of fighting viruses.
Manjaro 64bit on the main box -Intel(R) Core(TM) i7 CPU 920 @ 2.67GHz and nVidia Corporation GT200b [GeForce GTX 275] (rev a1. + Centos on the server - Arch on the laptop.
"There are no stupid questions - Only stupid answers!"

Return to “Linux News”