Trojan root Android device bypasses Google's security mode on Play Store
The malicious code hidden in this application is so smart that it deceives Google's security mechanism, pretending to be a clean application, then replacing it with a poisoned version for a short time. Security researchers at Kaspersky Lab discovered that the new malware was released in the form of a Google Play Store game application, hidden behind the colorful block puzzle game that was downloaded at least 50,000 times before being removed.
Named Dvmap, this Android root malware disables the device's security settings to install a third-party malicious application and inserts a malicious code and system runtime library device to gain root access. phone.
"To overcome the security of Google Play Store, this malware creator used a very interesting method. They downloaded a clean application to the Store at the end of March 2017, then updated with the poisoned version in a short period of time, "the researchers said. "Normally, they will upload a clean version later on the same day. They did it at least 5 times between April 18 and May 15."
How it works Dvmap malware
The Trojan works on both 32-bit and 64-bit versions of Andorid, once installed, it will attempt to gain root access to the device and install some modules on the system, including some written in Chinese. together with standalone application named com.qualcmm.timeservices.
The root of the Android phone is in the puzzle game application
To ensure that the infected module can be run by the system, the malware overwrites the system's runtime library, depending on the version of the user's Android device. To complete the installation of the stand-alone application, the system's authorized trojan will turn off Verify Apps and adjust the system settings, allowing applications to be installed from third parties.
"In addition, it can give the com.qualcmm.timeservices application the Administrator Administrator administrative rights without user intervention, just by running the command. That's a very different way to gain administrative rights." This third-party application will connect the infected device to the attacker's server, giving complete control of the device to the hacker.
However, researchers still do not know which Android device is infected with the command, so it is unclear what kind of file it is executing, but it could be an ad file or a poison.
How to protect the phone from the Dvmap malware?
Researchers are still testing the malware, but users who have installed the game are advised to back up phone data and perform data reset to avoid malware attacks.
To protect your phone from such applications, always be cautious of untrusted applications, especially when downloading from Google Play Store. Remember to only grant application verification rights when the content is relevant to the purpose of the application. Don't forget to read the user comments section before installing. In addition, anti-malware applications on your phone can detect and block malware before they infect your phone.
You should read it
- Hackers are taking advantage of the Store to distribute malware
- New bank trojan detection on Android Red Alert
- How to detect and remove malware Agent Smith on Android
- Detecting Android malware can easily steal OTP code without the victim knowing
- How to remove malicious software (malware) on Android applications?
- Mobile malware infection rate increased by 400% in the past year. Android has the highest rate
- What is Clipper Malware? How does it affect Android users?
- Sockbot malware was discovered in applications on Google Play Store
May be interested
- Detected 4 banking trojans in 11 apps on Google Play Storebanking trojans are designed to steal banking credentials and other sensitive data.
- How to root Android does not need a computer with KingRootwith kingroot, users will get a rooted android device in minutes without using a computer. read this article to learn how to do it!
- How to Add a Device to the Google Play App Storewhen you add a device to google play, you can access previously purchased apps, movies, music, books, and other content on the new device. you can add android devices very easily by simply signing in with the same google account. if you use an amazon fire tablet, you can choose from several alternatives to download the play store and access all android apps. you can't add ios (iphone, ipad) or windows devices to google play.
- 4 ways to fix DF-DLA-15 errors during the download process on Play Storeduring the download of the application from the play store to the android device, some users reflect that they cannot download the application and on the device screen an error message 'can't be downloaded. Đang thử lại, và nếu vấn đề đã tiếp tục, get help troubleshooting. (lỗi khi lấy thông tin từ máy phục vụ. [df-dla-15] '.
- 10 Magisk Module 'must have' for your Android deviceamong the ways to root android phones, magisk is considered the best way. this is a systemless method, meaning that it doesn't really change the android system partition. this allows offline phone root status with security applications and is also easier to unroot.
- Google declined to add 55% of the new Android application to Play Store in 2018, but that's not enough!according to google's disclosure in a comprehensive review of the google play store situation in 2018, the company declined many more new android applications to its platform, falling in about 55% more than 2017
- Root way of Android phones 7.0 / 7.1 Nougat with KingoRootandroid 7.0 / 7.1 nougat has been officially released for a while. as the latest operating system, many users wonder how to root android quickly and easily. kingo offers android users a safe, fast and rooted android phone.
- Decode all errors that appear on Google Play and how to fix them (Part 3)during the installation or updating (update) of applications such as facebook, messenger, whatsapp, ... some users encounter a fix play store error 11 error. usually the simplest solution to fix the error is to restart the android device. but this solution is only temporary, or sometimes it cannot fix the fix play store error 11.
- Instructions on how to unroot Android devicesthere are many people after having rooted their android device and used it for a while, they want to return to the state as if they were not rooted. so how to unroot your android device?
- Instructions for root steps of Galaxy Note 5 phoneif you want to remove unwanted bloatware on galaxy note 5 device or simply block ads on any application, or want to install incompatible applications ... you can do so. root your device.