Dr. Web Discovered Trojan that exploits Android Applications Spreading New Vulnerability

drwebBANGALORE, India- August 23, 2013

Dr.WEB, Russian developer of information security software, discovered the first malignant application for Android that spreads by exploiting the vulnerability Master Key. Android.Nimefas.1.origin can send text messages, transmit confidential information to criminals and allows intruders to remotely execute certain commands on the infected mobile device. Currently the Trojan is spread with games and applications which are available for downloading from a Chinese catalogue of applications for Android. However, it is possible that in the near future, there will be more malware exploiting the vulnerability Master Key and thus the threat geography will expand too.

When information about the vulnerability Master Key appeared in the public domain, most security experts were confident that criminals will take advantage of it sooner or later/ since technically the flaw is quite easy to exploit. Indeed, a corresponding exploit appeared in less than a month after details of the vulnerability had been disclosed.

The recently discovered Trojan, dubbed by Dr.Web as Android.Nimefas.1.origin, spreads with Android applications as a modified dex-file located in the same directory as the original dex-file of the program. Recall that the vulnerability Master Key concerns installation of applications under Android: if an apk-package contains a subdirectory with two files that have the same name, the operating system verifies the digital signature of the first file, but installs the second one, whose signature hasn’t been validated. Thus, intruders bypass the security mechanism that prevents installation of applications that have been modified by a third party.

When launched on a device, the Trojan first checks if a service of a known Chinese anti-virus is running in the system.

If at least one such service is detected, Android.Nimefas.1.origin searches for the files “/system/xbin/su” or “/system/bin/su” to determine if root access is available. If a file is found, the Trojan process is terminated. If none of the above conditions is met, the malware keeps running.

Android.Nimefas.1.origin sends the device’s IMSI at a phone number, chosen at random from the available list.

After that the Trojan sends short messages to all numbers found in the infected device’s phone book. The message text is downloaded from a remote server. Information about contacts to which the message has been sent, it transferred to the same server. The malware can send arbitrary SMS messages to various numbers. All the necessary data (message text and phone numbers) is acquired from a command and control server. The Trojan can also hide incoming messages from the user. A corresponding filter to conceal messages by their text or number is also downloaded from attackers’ server.

Currently, the remote server, used by cybercriminals to control the malware, is no longer functioning.

All devices running Dr.Web anti-virus for Android are protected from Android.Nimefas.1.origin: the technology Origins Tracing™ makes sure that Dr.Web detects this Trojan. In addition, an apk-file that contains this malware is detected by Dr.Web as Exploit.APKDuplicateName.

 

About Dr.WEB

Doctor Web is a Russian developer of information security software. Dr.WEB anti-virus products have been developed since 1992. They have always shown perfect results detecting malicious programs of all types and comply with international security standards. Our numerous customers around the world are clear evidence of the utmost trust placed in our products.