3.3 Trojan Programs in Mobile Communication Systems
231
intercepts the traffic does not reveal itself in any way, and its detection is virtually
impossible.
But secret services, of course, have the widest possibilities in terms of tapping.
NSA, for example, forced the US organizations it could reach to leave hardware
Trojans which helped discredit many security standards that were considered reliable
and used by multiple organizations and regular users [15].
In 2012, the agency was already gathering data about 70% of mobile networks of
the world. They even managed to wiretap the GSM Association—the international
organization of telecommunication operators, which develops recommendations for
new communication standards.
The agency also installed implants in various applications for mobile devices,
including BlackBerry phones, which were considered extremely well protected.
These smartphones were used by famous politicians, including the US Ex-President
Barack Obama, German Chancellor Angela Merkel, and many other officials from
other countries.
This is only a handful of examples, far from a comprehensive list of tapping issues.
In fact, this list is much longer, and we are talking only about the known methods of
tapping and data theft from mobile devices. That is, we’re only talking about the top
of the iceberg.
3.3.3 Embedded Trojan in Chinese Smartphones Nomu
and Leagoo
In late 2017, Dr. Web’s specialists warned users that the firmware of a number of
mobile phones “out of the box” can contain an Android.Triada Trojan [16]. Such
Trojan is embedded in the system process Zygote, which is responsible for starting
programs on mobile devices. Due to Zygote infection, the Trojan penetrates processes
of all working applications, acquires their privileges, and functions as a whole with
them.
While other types of this family of Trojans previously found by researches
tried to obtain root privileges for performance of malicious operations, the Trojan
(Android.Triada.231) is built into the system library libandroid_runtime.so.
Modified version of the library was found on several mobile devices at once. In
particular, Dr. Web’s report mentions smartphones Leagoo M5 Plus, Leagoo M8,
Nomu S10, and Nomu S20. According to the specialists of the company, “the libandroid_ runtime.so library is used by all applications; therefore, the malicious code is
found in memory of all launched applications in memory.”
The Trojan is built into libandroid_runtime.so in such manner that it takes control
every time an application on the device enters a record in the system log. As Zygote
starts working before other programs, initial start-up of the Trojan is performed
through it.
231
intercepts the traffic does not reveal itself in any way, and its detection is virtually
impossible.
But secret services, of course, have the widest possibilities in terms of tapping.
NSA, for example, forced the US organizations it could reach to leave hardware
Trojans which helped discredit many security standards that were considered reliable
and used by multiple organizations and regular users [15].
In 2012, the agency was already gathering data about 70% of mobile networks of
the world. They even managed to wiretap the GSM Association—the international
organization of telecommunication operators, which develops recommendations for
new communication standards.
The agency also installed implants in various applications for mobile devices,
including BlackBerry phones, which were considered extremely well protected.
These smartphones were used by famous politicians, including the US Ex-President
Barack Obama, German Chancellor Angela Merkel, and many other officials from
other countries.
This is only a handful of examples, far from a comprehensive list of tapping issues.
In fact, this list is much longer, and we are talking only about the known methods of
tapping and data theft from mobile devices. That is, we’re only talking about the top
of the iceberg.
3.3.3 Embedded Trojan in Chinese Smartphones Nomu
and Leagoo
In late 2017, Dr. Web’s specialists warned users that the firmware of a number of
mobile phones “out of the box” can contain an Android.Triada Trojan [16]. Such
Trojan is embedded in the system process Zygote, which is responsible for starting
programs on mobile devices. Due to Zygote infection, the Trojan penetrates processes
of all working applications, acquires their privileges, and functions as a whole with
them.
While other types of this family of Trojans previously found by researches
tried to obtain root privileges for performance of malicious operations, the Trojan
(Android.Triada.231) is built into the system library libandroid_runtime.so.
Modified version of the library was found on several mobile devices at once. In
particular, Dr. Web’s report mentions smartphones Leagoo M5 Plus, Leagoo M8,
Nomu S10, and Nomu S20. According to the specialists of the company, “the libandroid_ runtime.so library is used by all applications; therefore, the malicious code is
found in memory of all launched applications in memory.”
The Trojan is built into libandroid_runtime.so in such manner that it takes control
every time an application on the device enters a record in the system log. As Zygote
starts working before other programs, initial start-up of the Trojan is performed
through it.
