232
3 Hardware Trojans in Electronic Devices
After initialization, the malware performs preliminary setting of a number of
parameters, creates a working catalog, and checks the environment it is operating
in. If malware (malicious software) operates in the Davlik medium, it intercepts one
of the system methods, which helps monitor launches of all applications and start
malicious activities immediately after.
As the Trojan was introduced into the above library at the level of the source
code, the researchers believe that the distribution of Trojans was organized either by
insiders or by unscrupulous partners of device manufacturers, who participated in
the creation of firmware.
The main task of Android.Triada.231 is hidden launch of additional malware
modules that can load other components of the Trojan. To launch them, the Trojan
checks the presence of a special subdirectory in the previously created working
directory. Its name needs to contain the value MD5 of the software package of the
application, the process of which is infected by the Trojan.
If the subdirectory is successfully found, the Trojan looks for the file 32.mmd
or 64.mmd (for 32-bit and 64-bit operating systems, respectively). After detecting
the file, the Trojan decrypts it and saves it under the name libcnfgp.so, after which
loads it into the RAM using one of the system methods and deletes the decrypted file
from the device. If the required object is not found, the Trojan looks for 36.jmd. It
is also decrypted, saved under the name mms-core.jar, and launched using the class
DexClassLoader, after which the created copy is deleted from the device.
As a result, Android.Triada.231 can introduce virtually any Trojan modules into
operation of any programs and influence their work. For example, Trojan operators
can command downloading and launching malicious plugins to steal confidential
data and information from banking applications, modules for cyberespionage, interception of correspondence from social media, Internet messengers, and so on. The
Trojan is also capable of extracting the module Android.Triada.194.origin from the
library libandroid_runtime.so. Its main function is downloading additional malicious
components, as well as ensuring their interaction.
The researchers note that the Trojan cannot be deleted by conventional methods;
it is necessary to reinstall the clean firmware.
3.3.4 Expanding Possibilities of Mobile Phones Due
to Specialized Modules
You can use your mobile phone to control nearly everything!
For example, a small external module for mobile phones developed more than
10 years ago (Fig. 3.7) allowed the user to
• Implement security functions;
• Perform acoustic control of a room;
• Analyze geomagnetic fields;
• Use a passive infrared detector as soundless alarm system;
3 Hardware Trojans in Electronic Devices
After initialization, the malware performs preliminary setting of a number of
parameters, creates a working catalog, and checks the environment it is operating
in. If malware (malicious software) operates in the Davlik medium, it intercepts one
of the system methods, which helps monitor launches of all applications and start
malicious activities immediately after.
As the Trojan was introduced into the above library at the level of the source
code, the researchers believe that the distribution of Trojans was organized either by
insiders or by unscrupulous partners of device manufacturers, who participated in
the creation of firmware.
The main task of Android.Triada.231 is hidden launch of additional malware
modules that can load other components of the Trojan. To launch them, the Trojan
checks the presence of a special subdirectory in the previously created working
directory. Its name needs to contain the value MD5 of the software package of the
application, the process of which is infected by the Trojan.
If the subdirectory is successfully found, the Trojan looks for the file 32.mmd
or 64.mmd (for 32-bit and 64-bit operating systems, respectively). After detecting
the file, the Trojan decrypts it and saves it under the name libcnfgp.so, after which
loads it into the RAM using one of the system methods and deletes the decrypted file
from the device. If the required object is not found, the Trojan looks for 36.jmd. It
is also decrypted, saved under the name mms-core.jar, and launched using the class
DexClassLoader, after which the created copy is deleted from the device.
As a result, Android.Triada.231 can introduce virtually any Trojan modules into
operation of any programs and influence their work. For example, Trojan operators
can command downloading and launching malicious plugins to steal confidential
data and information from banking applications, modules for cyberespionage, interception of correspondence from social media, Internet messengers, and so on. The
Trojan is also capable of extracting the module Android.Triada.194.origin from the
library libandroid_runtime.so. Its main function is downloading additional malicious
components, as well as ensuring their interaction.
The researchers note that the Trojan cannot be deleted by conventional methods;
it is necessary to reinstall the clean firmware.
3.3.4 Expanding Possibilities of Mobile Phones Due
to Specialized Modules
You can use your mobile phone to control nearly everything!
For example, a small external module for mobile phones developed more than
10 years ago (Fig. 3.7) allowed the user to
• Implement security functions;
• Perform acoustic control of a room;
• Analyze geomagnetic fields;
• Use a passive infrared detector as soundless alarm system;
