DKFBootKit - First Android BootKit Malware
NQ Mobile Security Research Center has recently uncovered a new malware DKFBootKit. This malware is identified when monitoring and analyzing the evolution of earlier DroidKungFu variants. What sets DKFBootKit apart from malware like DroidDream, is that DKFBootKit replaces certain boot processes and can begin running even before the system is completely booted up.
DKFBootKit repackages legitimate apps by enclosing its own malicious payloads in them. However, the victim apps it chooses to infect are utility apps which require the root privilege to work properly. NQ says the malicious code has already infected 1,657 Android devices in the past two weeks and has appeared on at least 50 different mobile apps.
These apps seem to have legitimate reasons to request root privilege for their own functionality. It is also reasonable to believe that users will likely grant the root privilege to these apps. DKFBootKit makes use of the granted root privilege for other malicious purposes, namely comprising the system integrity.
In order to avoid being infected by this beast, NQ recommends three commonsense steps:
- First, don't download any apps from sketchy app stores.
- Second, don't accept app permissions from unknown sources and always be sure to read the permissions an app is requesting.
- Third, download a security app that can scan your apps for you to search for malicious code.
Like It? Share It
0 comments:
Popular Posts
-
It's been about three years since Microsoft unveiled a new version of Office, and particularly with Windows 8 just months away from ...
-
There's general agreement that Sony stumbled out of the gate with the PlayStation 3. Months of intense hype were followed by a la...
-
Latest Windows Phone 8 rumor suggests that current Windows Phone devices will receive the update Microsoft has yet to come forward wi...
-
Microsoft is holding an invitation-only press event in San Francisco today at which it is expected to debut the next version of its...
-
Gaming & Gadgets Microsoft kick-started the "next-generation" of gaming on November 22, 2005, when the company release...