3.3 Trojan Programs in Mobile Communication Systems
251
According to the Android Security Bulletin, the patch released in December 2016
fixed 74 vulnerabilities, 11 of which were critical. They made it possible to get
superuser rights and remotely execute arbitrary code of the virus writer. Such security
patches are released once a month; only the owners of Google smartphones (Nexus,
Pixel, and low-cost Android One) can count on them. No one guarantees creation of
security patches for mobile devices from other manufacturers.
The statistics show that fixing everything is impossible; even after installation of
fresh updates, the system will still have a couple of loopholes, which will provide
entry for the intruders.
Who is in the risk zone?
We’re used to thinking that our knowledge is enough to protect us from becoming
victims of malware. Moreover, if the set of applications used has been established for
a long time, there seems to be nothing to worry about. However, there are exceptions
from any rule. In which cases is the infection risk still real?
Outdated OS
First of all, endangered are the users of old versions of Android OS. According
to the official data, as of February 2017, 68% of Android smartphones work on
Lollipop versions 5.1 and older. However, hard people go on Google, its patches are
actually useful: they cover most of the known loopholes. However, as a rule, they
cover vulnerabilities for the latest Android versions and only for Google devices.
However, even owners of regularly updated devices shall not fully rely on standard
protection mechanisms.
The sixth version of the Android barely started working when the authors of the
Gugi Trojan (Trojan- Banker.AndroidOS.Gugi.c) learned to bypass protection and
cash bank cards of naive users. In 2016, 93% of the victims (about 5000) were located
in the Russian Federation.
Unofficial sources
It would be stupid to blame users for installation of applications from unofficial sources—after all, free downloading is one of Android’s advantages over iOS.
Malware stored on file exchangers can assume any form: a program can mimic a
game or a useful application.
In February 2016, Trend Micro discovered a Trojan that could intrude on the root
system of a phone. The users downloaded the file and launched it; the malware called
ANDROIDOS_LIBSKIN.A collected the account details and sent it to a remote
server. According to TrendMicro, it only took the virus several days to spread across
169 countries, including Russia: A huge base of personal data was collected. It is yet
to be discovered who used or uses it and for what purpose.
Dr. Web specialists note that the hazard of this malware was embedded in the
very infrastructure of the Android platform. Protection means cannot treat system
areas by default, which is used by intruders. Moreover, not all antiviruses can cure
system areas—the only such antivirus in the Dr. Web range, for example, is Dr. Web
Security Space.
Précédent

- 271/839

Suivant