Many cheap Android smartphones are 'promotional' codes for users
Avast has discovered a kind of malware called Cosiloon that is included in many cheap Android phones that are not certified by Google.
This malware will display ads for operating system applications, enticing users to download. Affected smartphones from ZTE, Archos and myPhone.
This malware contains:
- A dropper (a malicious program in the / system partition designed to "install" some types of viruses) is only displayed in the list of system apps in Settings. This Dropper has 2 different names 'CrashService' and 'ImeMess'.
- A payload (a code that runs on the victim's computer, used to perform certain activities, or is used to connect to an attacker's machine) is downloaded from a website.
Avast said: " The XML file contains information regarding what to download, which services to start, and contains a whitelist to exclude specific countries and devices from being affected." But Avast only saw a few devices that were included in this list in the early versions, and the countries never appeared, and now Cosiloon's entire URL is programmed hard into the APK file. No device or country is excluded.
Dropper is part of the system firmware and the user is not easy to remove it.
See more:
- Warning: New malicious code is infecting about 500,000 router devices
- Top 12 most dangerous backdoor in computer history
- 7 kinds of ransomware you didn't expect
You should read it
- Discover a new kind of malicious code that can record the phone call to extort money
- 10 million Android devices are preinstalled with malicious code from the factory
- Appearing dangerous Android malicious code specializing in stealing chat content on Facebook Messenger, Skype ...
- Warning: The new Facebook virus, a malicious code that is spreading rapidly through Messenger
- 14 games on the App Store contain malicious code, iPhone users be careful
- Detect new malicious code to attack Android device
- Discovered a new line of malicious Android code that steals user data on the electronic application market
- Malware Judy attacked more than 36.5 million Android phones
- Warning: New malicious code is infecting about 500,000 router devices
- Android apps contain malicious code that uses motion sensors to avoid detection
- How to check if your Android phone is infected with Android Gooligan malware?
- Discovered a group of hackers who use secret code to spy on 21 countries
Maybe you are interested
Instructions for installing and using Avast Free Antivirus to effectively remove viruses on your computer
Avast Secure Browser: Chromium-based browser for secure web surfing
Should you choose Brave browser or Avast Secure Browser?
Avast Free Antivirus 20.10.2442
Troubleshoot problems with Avast Free Antivirus in Windows 10
How to remove Avast Free Antivirus completely from the computer