Pre-installed malware on Android devices made $115k revenue in 10 days

Check Point Mobile Security Team discovered a massive, on-going malware campaign that so far has claimed 5 million victims. Reportedly, the malware dubbed as RottenSys has managed to create a massive army of botnets comprising of 5 million mobile devices from across the globe.

The malware is hidden in a System Wi-Fi service application that is already installed-by-default on countless models of smartphones manufactured by prominent companies including Honor, Huawei, GIONEE, Samsung, Oppo, Vivo, and Xiaomi.

According to the blog post, Researchers believe that these firms cannot be held directly responsible for the malware and the devices must have been infected during supply chain phase. Probably the distribution firm or a rogue employee is to be blamed for the installation of malware.

It is worth noting that the affected devices were shipped through the same Hangzhou, China-based mobile devices distributor Tian Pai. However, the researchers are not yet sure if this particular firm has any direct involvement in the installation of RottenSys malware.

Check Point researchers claim that RottenSys is a highly sophisticated and advanced program that acquires almost all sensitive permissions on an Android mobile phone to perform its malicious acts. Such as it asks for silent download permission (DOWNLOAD_WITHOUT_NOTIFICATION permission), accessibility service permission and user calendar read access privilege. The campaign started in September 2016 and until March 12, 2018, it has infected 4,964,460 devices.

The fake Wi-Fi service app manages to evade detection by employing a submissive approach in the beginning and doesn’t instantly start its malicious tasks. Later, the malware dropper component communicates with its C&C server to receive a list of components it needs. The required component is actually the malicious code. The malware is capable of assembling an army of botnets and within only ten days attackers have made profits of approx. $115,000.

“RottenSys is an extremely aggressive ad network. In the past 10 days alone, it popped aggressive ads 13,250,756 times, and 548,822 of which were translated into ad clicks,” read the blog post from Check Point.

Originally the malware was used to display fraudulent ads on mobile devices’ home screen. Check Point researchers claim that since the onset of 2018, malicious threat actors have been trying to improve the malware code by adding a new module and created brand new malware campaign using the same C&C server. This campaign has remained active from February 2018.

“The attackers plan to leverage Tencent’s Tinker application virtualization framework as a dropper mechanism. The payload which will be distributed can turn the victim device into a slave in a larger botnet,” read the blog post from Check Point.

The botnet can perform a variety of tasks such as installing additional apps discreetly, automating the UI. Researchers identified that a part of the botnet’s controlling mechanism is implemented in Lua scripts. The attacker can thus, re-use the existing malware distribution channel without any intervention and gain control of millions of devices.

Users can easily uninstall RottenSys dropper if only they are aware of the exact package name that is to be deleted. Currently, researchers are unsure how the hackers would use the army of botnets that they have assembled so far.

Source: Check Point

Related Posts