Security Professionals Alert Users On New Android Trojan

Security Professionals Alert Users On New Android Trojan

By:


In the recent times, security researchers have frequently found vulnerabilities in mobile applications and operating systems supporting them. Many experts have warned users against increased mobile security threats during the current year. Mobile applications add to the convenience of users. The growing popularity and wide usage of mobile devices have encouraged attackers to exploit security flaws. Recently, security researchers at Lookout mobile security identified a new Android Trojan disseminated through application forums targeting Chinese users. The Trojan has been identified as HongTouTou or ADRD.

The Trojan is integrated in repackaged Android applications. Security researches at Lookout mobile security have detected fourteen different variants of the malware. When a HongTouTou incorporated device starts, the Trojan reportedly transmits International Mobile Equipment Identity (IMEI) and International Mobile Subscriber Identity (IMSI) number to a remote host. The remote host sends a set of keywords and uniform resource identifier (URI) to the Trojan. The Trojan allegedly seeks additional user privileges. The malware executes covert keyword searches and clicks on select links from the output provided by the search engine. The words appear to be provided to the search engine by a legitimate user through a mobile web browser.

The malware may also install Android package file (APF), capable of monitoring information transmitted through SMS messages. The APF is also capable of intercepting and inserting potential spam text in a SMS message. Research has not identified any breach of genuine applications of Android.

Attackers take advantage of the lack of security awareness among mobile users to inject malicious malware and extract private information. IT training and security awareness programs may help users in understanding different types of mobile threats.

Security professionals must regularly upgrade their skills through online training programs to face the impending challenges in the domain of mobile security.

Usually, penetration testers conduct in-depth security evaluation and mitigate vulnerabilities. Manufactures face constant challenge of developing innovative and secured products. Security researchers have advised users to be wary of opening applications from untrusted sources. Users must allow only those privileges, which match the features provided by the applications. Installation of mobile security applications may help users in safeguarding their devices from malware and other security threats.


About the Author:

penetration testers, online training



Article Originally Published On: http://www.articlesnatch.com


|

Loading...
Related....
Videos...

Recent Security Articles

Comments

Still can't find what you are looking for? Search for it!

Loading

Copyright 2005-2011 ArticleSnatch, LLC - All Rights Reserved.
Privacy Policy | Terms of Service.