Skip to main content

New Android adware reportedly “nearly impossible” to remove

360 Security review

Lookout has discovered a new form of adware that roots a device after the user installs it, then entrenches itself as a system application. This makes it impervious to any normal means of deleting it, even factory resetting the device.

This is a new, more sophisticated version of typical adware, which tends to make itself annoying by constantly pushing ads at the user. Since this form of malware has root access, it doesn’t need to annoy the reader, and most users probably won’t even know they’ve been infected. It’s effectively a family of trojan viruses.

Lookout discovered that this family of trojans hides inside legit apps like Candy Crush, Google Now, Facebook, NYTimes, Okta, Twitter, WhatsApp, Snapchat, and over 20,000 others. Infected versions of these applications are not available on the Google Play store and must be downloaded from third party stores. Since most instances of this malware leave the host app virtually unaltered, users may not notice the sneaky little culprit that snuck in on it.

Lookout reports that successfully embedded instances of this malware are “nearly impossible” to remove, and that the only solution for most users will be to purchase a new phone. Adware with this kind of power is obviously a security risk. Apps typically aren’t given access to files created by other applications, but root access bypasses this safeguard and could expose infected devices to fraud and identity theft.

Lookout has identified three different families of this form of trojan malware: Shuanet, Kemoge (or “ShiftyBug”), and GhostPush. These families have separate designers but share 77% of their code, meaning that even if those responsible for creating them are not working together, they are at the very least aware of each other. The highest rates of infection are in the United States, Germany, Iran, Russia, India, Jamaica, Sudan, Brazil, Mexico, and Indonesia.

So is this really that big of a deal though? While the situation might sound dire, in reality, the odds of being infected by such a trojan probably is pretty low. As already mentioned, these infected apps are found in 3rd party stores, so if you stick to official channels — you should have very little to worry about.

Comments

Popular posts from this blog

A Google Engineer is reviewing all USB Type-C chargers on Amazon to inform customers which ones are safe for use on their devices

The USB Type-C take over has already started, and as this year comes to an end, we expect to see a few more smartphones and tablets hit the market bundling compatibility for the third-generation connection. As it stands, handsets that currently feature Type-C ports only ship with a single cable and that annoyingly doesn’t support computer connectivity, so if users want to transfer files to their devices, they have to purchase an additional wire or adapter. However, these accessories aren’t cheap, so customers veer towards the more affordable, third-party cables readily available on marketplaces, such as Amazon and eBay, but that’s not a good thing. Many consumers have reported that these chargers have caused harm to their handsets, so Google Engineer Benson Leung has taken it upon himself to purchase a selection of Type-C connectors from Amazon to test and see if they meet the standard specifications for use on his Nexus device. So far, Leung has been through seven cables and clai...