China targeted by new Android Trojan

  • 8 February 2014
  • 0 replies
  • 1 view

Userlevel 7

Bootkit attack hits '350,000 devices'

By Richard Chirgwin, 5th February 2014  Russian security researchers are warning about an Android Trojan called Oldboot that has infected 350,000 devices worldwide.
 
According to this post at Dr Web, Oldboot has a characteristic that makes it hard to deal with: some of the Trojan's components are loaded into the boot partition of the Android file system. By acting as a bootkit, the researchers claim, it's less likely to be deleted.
 
The “very unusual” technique involves:
“placing one of the Trojan components into the boot partition of the file system and modifying the init script which is responsible for the initialisation of OS components. When the mobile phone is turned on, this script loads the code of the Trojan Linux-library imei_chk (Dr.Web Anti-virus detects it as Android.Oldboot.1), which extracts the files libgooglekernel.so (Android.Oldboot.2) and GoogleKernel.apk (Android.Oldboot.1.origin) and places them in /system/lib and /system/app, respectively.”
 
Full Article
 

0 replies

Be the first to reply!

Reply