1. Download our Official Android App: Forums for Android!

Infected Android app

Discussion in 'Android Apps & Games' started by odatkid, Mar 1, 2011.

  1. odatkid

    odatkid Well-Known Member
    Thread Starter
    Rank:
    None
    Points:
    38
    Posts:
    163
    Joined:
    Jan 23, 2011

    Jan 23, 2011
    163
    10
    38
    Male
    Florida
    A rogue Android app that's been tweaked by hackers can hijack a smartphone and run up big texting bills before the owner knows it, Symantec said today. The newest in a line of compromised Android apps, is Steamy Window, a free program that Chinese hackers have modified, then re-released into the wild. The cyber criminals grabbed a copy of Steamy Windows, then added a backdoor Trojan horse - "Android.Pjapps" by Symantec's label -- to the app's code. The reworked app is then placed on unsanctioned third-party "app stores" where unsuspecting or careless Android smartphones find it, download it and install it.
    The Trojan planted by the malware-infected Steamy Windows can install other applications, monkey with the phone's browser bookmarks, surreptitiously navigate to Web sites and silently send text messages.
    The last is how the criminals make money. The Trojan lets them send SMS [short message service] messages to premium rate numbers for which the hackers are paid commissions. Android.Pjapps also has a built-in filter that blocks incoming texts from the user's carrier, a trick it uses to keep victims in the dark about the invisible texting. It monitors inbound SMS texts, and blocks alerts telling you that you've already exceeded your quota, Smartphone owners then wouldn't be aware of the charges they've racked up texting premium services until they receive their next statement.
    Symantec found the cloned Steamy Windows app on a Web site hosted by Chinese servers.
    The practice of altering legitimate Android apps to carry malware isn't new -- earlier this year, security experts warned that Monkey Jump was being cloned by criminals for the same purpose -- but the bogus Steamy Window app shows that hackers are getting better at reworking mobile software.
    Android smartphones are an attractive target for hackers, because of their increasing popularity and because, unlike Apple's iOS, users can install apps downloaded from third-party distribution sites.
    Smartphone owners should be wary of unauthorized app stores, Downloading an app from one of these [third-party] sites is like downloading a Windows app from a 'warez' site.
    Look at the permissions the app requests when it installs. A [rogue] app will request more permissions than the legitimate version.
    Symantec published an analysis of Android.Pjapps on its Web site Monday.
    The legitimate Steamy Window app for Android can be downloaded from Google's Android Market.
     

    Advertisement

  2. Tiny Turtle

    Tiny Turtle Member
    Rank:
    None
    Points:
    36
    Posts:
    36
    Joined:
    Oct 5, 2010

    Oct 5, 2010
    36
    7
    36
    Newspaper prepress (nights)
    Stockholm, Sweden
    Great idea with the all-bold approach - Kinda like ALL CAPS, but more annoying.
     
    nvrfgt343 likes this.
  3. shrink57

    shrink57 Android Expert
    Rank:
    None
    Points:
    143
    Posts:
    1,529
    Joined:
    Dec 19, 2009

    Dec 19, 2009
    1,529
    149
    143
    South Florida
    The ones that use the shady sites to save a buck and screw a developer (appbucket just to mention one) deserve what they get.
     
  4. Tempusfugit

    Tempusfugit Android Enthusiast
    Rank:
    None
    Points:
    78
    Posts:
    588
    Joined:
    Dec 11, 2010

    Dec 11, 2010
    588
    74
    78
    +1 and then you have to ignore the SERVICES THAT COST YOU MONEY - SEND SMS permission for a live wallpaper or a game.


    Hide yo kids, hide yo husbans!

    Threat Assessment
    Wild
    Wild Level: Low
    Number of Infections: 0 - 49
    Number of Sites: 0 - 2
    Geographical Distribution: Low
    Threat Containment: Easy
    Removal: Easy
    Damage
    Damage Level: Low
    Payload: Opens a back door on the compromised device.
    Distribution
    Distribution Level: Low
     
  5. Steven58

    Steven58 Reformed PH
    Rank:
     #3
    Points:
    3,933
    Posts:
    32,986
    Joined:
    Feb 19, 2010

    Feb 19, 2010
    32,986
    25,406
    3,933
    Male
    I've been using it for over almost a year and have had no trouble with it.
     
  6. LittleAnt

    LittleAnt Well-Known Member
    Rank:
    None
    Points:
    38
    Posts:
    157
    Joined:
    Feb 23, 2011

    Feb 23, 2011
    157
    19
    38
    Aerospace Engineer
    Los Angeles, CA
    don't like it then don't read it.
     
  7. jdizzle

    jdizzle Member
    Rank:
    None
    Points:
    16
    Posts:
    31
    Joined:
    Sep 27, 2010

    Sep 27, 2010
    31
    2
    16
    KS
    hey Tempusfugit, could you let me know what app you are using to assess your the threats on your phone?

    Thanks!
     
  8. Tempusfugit

    Tempusfugit Android Enthusiast
    Rank:
    None
    Points:
    78
    Posts:
    588
    Joined:
    Dec 11, 2010

    Dec 11, 2010
    588
    74
    78
    I just googled Android.Pjapps Symantec and that is from the symantec page.
     
    jdizzle likes this.
  9. AngryHatter

    AngryHatter Android Expert
    Rank:
    None
    Points:
    78
    Posts:
    973
    Joined:
    Jan 21, 2011

    Jan 21, 2011
    973
    92
    78
    QA Admin
    SoCal
    +1
     
  10. AngryHatter

    AngryHatter Android Expert
    Rank:
    None
    Points:
    78
    Posts:
    973
    Joined:
    Jan 21, 2011

    Jan 21, 2011
    973
    92
    78
    QA Admin
    SoCal
    If Symantic told me it was daytime, I'd go outside and check, first.
     
    TVCCS likes this.
  11. Tempusfugit

    Tempusfugit Android Enthusiast
    Rank:
    None
    Points:
    78
    Posts:
    588
    Joined:
    Dec 11, 2010

    Dec 11, 2010
    588
    74
    78
    I don't use their products, but they are a fairly reliable source for information on most viruses.
     

Share This Page

Loading...