‏إظهار الرسائل ذات التسميات How to Avoid Virus and Malware on Android. إظهار كافة الرسائل
‏إظهار الرسائل ذات التسميات How to Avoid Virus and Malware on Android. إظهار كافة الرسائل

الأحد، 12 أكتوبر 2014

iOS Trojan –Malicious Software, Chinese Creation




iOS Trojan
The Lacoon Mobile security researchers’ team have identified one of its first Apple iOS Trojan attacks to oppose communication of pro-democracy Hong Kong activists. Initial investigation indicates that the Trojan has an impressive number of surveillance capabilities.

The malicious software discovered has been dubbed Xsser mRat which uses social engineering to rob valuable data from jail broken devices while the users unknowingly tap on an install link in phishing messages from unknown users.

The malicious software has been created by Chinese hackers wherein it can obtain various range of personal information which could include the iOS address book, call logs, GSM identities, SMS messages, as well as the approximate geographical location which could be determined by the cell tower ID, pictures on devices together with passwords and other authentication data available in the iOS keychains that are used by Apple ID mail accounts and the other services.

The spyware has the capabilities of obtaining additional data in the cloud like the iOS version, MAC address, device version and phone number, IMSI and IMEI. When it is installed on any device, the Trojan automatically runs on rebooting, updating itself dynamically.

Xsser mRat Targets iOS Devices 

According to Lacoon Mobile Security, the so called virus, Xsser mRat, targets the iOS devices related to Android spyware which have been distributed widely in Hong Kong. In a blog post, it is also mention by Lacoon that Xsser mRat is connected with Android spyware infecting mobile users in Hong Kong which seems to be designed in helping to coordinate Occupy Central Hong Kong protesters and then prepare an attack.

Lacoon has also stressed on the importance of a cross platform mobile attack.It is very rare where cross platform attack could target iOS as well as Android devices, which shows that it could be conducted by some large organization or a big state. Considering that the attack has been used against protesters and executed by Chinese speaking attackers indicates its first iOS Trojan which has been linked to Chinese government cyber function.

The Xsser code has been written in Chinese which has led Lacoon to believe that the attack could be from sophisticated Chinese attackers. There is one hitch wherein the iOS user should have a jail broken device and Android should have a third party app download enabled

First Fully Advanced Operational Chinese iOS Trojan

The Xsser mRat is important since it is the first and most fully advanced operational Chinese iOS Trojan which is presently found. It can cross border with ease and is probably operated by a Chinese entity to spy on foreign companies, individuals or an entire government.

It infects the users’ devices through WhatsApp depending on their geographical proximity to the site of protests and as per Lacoon, Xsser had send out it first message to the user which states `Check out this Android app designed by Code4HK, group of activist coders, for the coordination of Occupy Central’.

When the download link is clicked by the user, they download an apk file unknowingly which presents them with a list of permission that needs to be approved and finally the user is lead to agree to application updates which on doing so, the application gets updated and activates the hidden features of the mRat

الثلاثاء، 24 يونيو 2014

How to Avoid Virus and Malware on Android


Android
Common sense is needed in keeping infected apps off the Android device which like any computer system, tends to get affected with malware and virus and Android too can get affected with it. Android has checks and balances which help to keep one safe most of which can be done with ease following the basic steps needed:

If you Don’t know what it is, Don’t Install it 

The first important step is if you don’t know about the app, do not install it. It is advisable to refrain from blindly installing Android application file which one may receive in email or linked to spam mail or even in various forums in the internet. Knowledge of the app is very essential before installation of the same.

Only install from Google Play or Reputed App Stores 

Caution should be exercised while installing app where most of them come in duplication which could be prone to viruses and malware. Apps should be installed from reputed app stores which can be done with safety and comfort. Random download from unreliable stores should be avoided which could save the device from virus and malware.

Uncheck `Install from Unknown Sources’

Android devices by default have access to Google Play ships with a lock which keeps application other than Google store from getting installed. This is one of the safest feature and with this locking system, the user gets a warning whenever an application makes an attempt in the installation from other app stores. Should the user have the inclination of installing an app, disabling the lock can be done by ticking of the `Unknown source’ in the security setting.

Read the Permission 

At the time of installing any app on the Android phone, either from Google Play or any other app stores, the app will declare permission to access to download on the phone and keyboard app need to record the keystrokes. Reputed app developers tend to lit the reasons in their listings of app though users also need to be somewhat vigilant

Most Trusted App Markets –Google Play/Amazon AppStore 

Malware and viruses on Android devices is something which the user should be aware of since they can send unwanted spam to anyone in your contacts in worst situations even rack up charged under the users’ accounts, though this can be easily avoided by making use of the tips mentioned above. Users should also be cautious while Sideloading apps especially of third party app stores.

 Downloading App files from locations besides Google Play Store and then manually installing them is known as Sideloading and is an essential step in accessing to apps which are not available. The recent hit game `Flappy Bird’, which is no longer avails in the Play Store can be manually sideloaded on the smartphones though at the time of installing the game from unknown sources, the user may tend to run the risk of infecting the phone with virus.

One should also a third party app store which promises free games along with other apps which normally come with a price. The most trusted app markets are Google Play and the Amazon AppStore. Installing anti-virus apps could also be helpful as an additional precaution which will occasional scan the device for malicious files, monitor the memory usage and provide alerts on any vulnerability in the system.