language
Detectat automat

Am preselectat Română și Romanian Leu (lei) pentru tine.

Autentificare
softwarebay.de
softwarebay.de
Pre-installed Malware Discovered on Android Smartphones
News › Cybersecurity › Pre-installed Malware Discovered on Android Smartp...
Cybersecurity

Pre-installed Malware Discovered on Android Smartphones

Pre-installed Malware Discovered on Android Smartphones

Security experts from Bitdefender have discovered a new wave of attacks known as Midnight Mimosa. This affects low-cost Android smartphones that are shipped with pre-installed malware. The malware is integrated directly into the firmware of the devices, meaning that buyers receive a new smartphone with malicious software already installed. The malware has system privileges, allowing attackers to install apps unnoticed, commit ad fraud, and turn the devices into private proxies. Bitdefender identified around 32 applications that were distributed via the malware framework.

These applications disguised themselves as everyday tools such as weather apps, file managers, and audio editors. A central issue is that attackers can execute downloaded code remotely without user intervention. The security researchers suspect that the malware was injected at some point in the supply chain of the devices. So far, it is unclear who is behind the attack and how exactly the malicious code made its way into the firmware. The researchers found firmware signed with certificates associated with the Chinese device manufacturer Shenzhen Zediel.

However, Bitdefender clarified that this association does not prove that Shenzhen Zediel authored or distributed the malware or was aware of it. The malware particularly affects Android devices with MediaTek chipsets. The campaign has impacted thousands of devices in over 150 countries over a period of about two years. Most victims have been reported in countries such as Mexico, France, Italy, the United States, Germany, Brazil, and Spain. Affected users report suspicious applications that reinstall themselves after being uninstalled.

A owner of a Doogee Fire 3 Max reported that an official firmware update infected the device with malware. After restoring an older firmware version, the malware disappeared, but it reappeared upon reinstalling the update. Some users indicated that manufacturers had released firmware updates that resolved the issue. However, manufacturers have not publicly explained how the malware entered the affected firmware. For owners of the affected devices, removing the malware proves to be challenging.

The security researchers recommend resetting the devices to factory settings, which, however, does not always guarantee the complete removal of the malware. The discovery of this malware campaign raises serious questions about the security of Android devices, especially in low-cost models. The incidents highlight the need for increased scrutiny of firmware before delivery to end consumers. According to Bitdefender, the affected models include the Doogee S200 X and the Cubot KINGKONG X. The security situation remains tense as researchers continue to seek solutions to protect the affected devices.

The malware campaign has already affected many users worldwide, and the exact number of affected devices could still rise. Researchers advise paying attention to the origin and security certificates when purchasing smartphones. The vulnerability not only affects user privacy but could also have far-reaching implications for network security. The malware could potentially be used for cyberattacks on larger networks, underscoring the urgency of the issue. Bitdefender researchers have documented the affected models and malware variants to enable better analysis and counteraction.

The security researchers are working to decipher the exact functioning of the malware and develop possible countermeasures. The discovery of this malware campaign could also lead to increased regulation and scrutiny of smartphone manufacturers to ensure consumer safety. The malware campaign has been intensively investigated in recent months, and results are expected to be published in the coming weeks. Researchers hope that by raising awareness of this threat, users will be more informed and make safer purchasing decisions. Bitdefender's security researchers have found that the malware is particularly widespread in devices with MediaTek chipsets.

Tags: Malware Android Security Bitdefender Cyberattacks

💬 Comentarii (0)

Scrie un comentariu

info Va fi publicat dupa moderare
chat_bubble_outline

Inca nu exista comentarii. Fii primul!