The researchers of Kaspersky have discovered new malware on Android. The uniqueness of the SoumniBot is the use of a technical turbullimit making use of some of the errors in the procedure for the extraction and analysis of the manifesto of the application. The functions are those of a trojan banking, so that the purpose of the criminal cyber is to collect information from the device, and to rob the people of a sensitive, including the credentials to access to the accounts of the business.
The first three techniques, the mjegullimi
Each pack APK file is a ZIP archive with the file AndroidManifest.xml in the directory root, which contains information about the components, licenses, and records for the application. SoumniBot uses three methods to bypass any measures of the certainty. The first one uses a value of the void kompresimi on the issue of the manifesto of the archive, by using the library libziparchive. Due to an error, analizuesi Google accepts any value other than 8, and it allows her to write the data to the pakompresuara, d.m.th. the data of the malware.
The head of the AndroidManifest.xml it contains the size of the file. However, due to an error, is shown in a size larger than that of the current. It allows you to add the code of the malware is not detected by Android. In the end, SoumniBot use a range name for the area of the names of the XML file AndroidManifest.xml. Analizuesi of Google to ignore the spaces in the names, so that the malware is not detected.
When you start the application, the infected, trojani the bank dismisses some of the parameters set up by the server at the remote. Then start to collect the information about your device, including your phone number, and the operator a mobile phone. After that, it zhbllokon IP address, the contact list, SMS, MMS, pictures, videos, a list of the applications installed and the certificates to the digital bank.
The Malware is hard to be removed, because the application of the virus is hidden. The distribution will almost certainly become the store of a third-party. Google, in fact, has communicated that none of the application SoumniBot has not been found in the Play Store.
Discussion about this post