Categorized | Sophos

New Android Trojan horse could prove costly

Evil AndroidSome vendors are calling it HongTouTou, others have named it Adrd, and Sophos (rather unimaginatively in my view!) treats it as a variant of Geinimi, but whatever your anti-virus product chooses to call it, there’s no denying that a new Trojan horse for Android smartphones is making headlines.

The latest Trojan horse for Google’s Android operating system has been seen posing in Chinese third-party app stores as legitimate programs such as Wallpaper apps.

The official Android Market, run by Google, does not appear to be carrying the malicious apps – but if you go “off-road” and choose to install software on your smartphone from elsewhere on the net, then you could be putting your device at risk.

Android application settingsFor this reason, the vast majority of Android users probably have little to fear. But those who do install applications from unknown sources (known as “sideloading”) do need to recognise that they might be putting their smartphone, data and potentially finances in danger.

Once installed, the malicious application can not only gather information about your smartphone (the device’s IMEI and IMSI), but it can also emulate clicks on particular search results – giving the visited websites the impression that it is a real mobile phone user choosing to visit their pages.

The assumption has to be that those behind the Trojan horse might be earning commission through the click traffic. Furthermore, of course, it could hurt you in your pocket by eating up data bandwidth.

Interestingly, the malicious code appears to have the ability to download updates for itself via the web, which could contain additional functionality.

Sophos has been detecting the Trojan as a variant of Troj/Geinimi-A since 00:15 BST on 15 February 2011.

For more information about the Trojan, check out the blog entry from the mobile security researchers at Lookout.

Related Posts

Comments are closed.

Security Status

Beware Facebook "Timeline" scams http://t.co/W5EW0cVv
5 months ago
Nigerian government (unknowingly) hosts phishing website http://t.co/uQd42ENw
5 months ago
PCMag Awards McAfee All Access its Editors’ Choice: SANTA CLARA, Calif.--(BUSINESS WIRE)--McAfee today announced... http://t.co/FakV7Vd8
5 months ago
RT @mikko: I hadn't noticed Google Maps has added 3D models of buildings. Here's a (very accurate) view of F-Secure HQ in Helsinki http://t.co/IKfAZlak
5 months ago
North Koreans aren't known for their online presence. But others may be lured into clicking Kim Jong-Il 'videos' too http://t.co/yQOon6YT
5 months ago
How to Protect Your Professional Reputation on Facebook Timeline http://t.co/I4bcR2VN
5 months ago
This is pretty impressive from @Softpedia: Facebook scans 2 trillion link clicks and blocks 220 million posts each day http://t.co/vKsn9gNl
5 months ago
Need for integrated approach to security in industrial control systems - http://t.co/tPBCNOow with @PikeResearch
5 months ago
Some free-based music we play at work http://t.co/xu5agZfc
5 months ago
Japan’s cyber defense weapon: a virus. It includes quotes by @Luis_Corrons via @InfosecurityMag
5 months ago