A new strain of Android malware has infected 25 million devices and modified legitimate apps with a malicious ads module, according to a report by the security company Check Point.
It's believed the malware originated from a Chinese internet company that helps Chinese Android developers publish and promote their apps in foreign markets. The malware was disguised as Google-related updaters and "vending modules," which hid its own app icons and automatically replaced already-installed legitimate apps with its own version without the user knowing. This lead the researchers to name the malware "Agent Smith" because its behavior is similar to the character in the film The Matrixof the same name.
The malware first appeared in popular third-party app store 9Apps and targeted mostly Indian, Pakistani and Bangladeshi users. However, of the 25 million affected devices, 303,000 infections were detected in the US, and 137,000 in the UK.
Apps that were modified include WhatsApp, Opera Mini, Flipkart, as well as software from Lenovo and Swiftkey. The malware detected which apps were installed, patched them with a malicious ads modules, and then re-installed them on the device. For the user, it simply looks like the app is being updated as expected. Once the update is complete, the owner of the malware can then profit from the newly included ads.
Check Point believes the same malware could also be used for more malicious purposes such as credit card theft, with the company's report stating, "due to [the malware's] ability to hide its icon from the launcher and impersonates any popular existing apps on a device, there are endless possibilities for this sort of malware to harm a user's device."
The security firm says they submitted data to Google and law enforcement agencies, and as of publishing no malicious apps remain on the Play Store. Nevertheless, the malware managed to survive for as long as it did because, despite the original vulnerability Agent Smith was based on being patched in Android years ago, developers did not sufficiently update their applications.
Malware like this, "requires attention and action from system developers, device manufacturers, app developers, and users, so that vulnerability fixes are patched, distributed, adopted and installed in time," Check Point says.
TopicsAndroidCybersecurity
(责任编辑:知識)
Singapore rolls out video
Parler ban pushes random app 'Parlor' to top of app store charts
Apple's MagSafe Duo is finally available for purchase
'This claim is disputed' Twitter meme is here to question your baseless statements
Pokémon Go is so big that it has its own VR porn parody nowIs Samsung's Galaxy Note7 really the best phone?
On this week's 。 MashTalk
。, Lance, Pete and I talk about the new hot smartphone in town: Samsung's Ga
...[详细]Netflix's 'Sir' is essential Indian cinema
In the first month of coronavirus lockdowns in the United States, when everyone began constantly scr
...[详细]Tinder sees massive rise in mentions of 'courting' and 'flirting' in bios
Romance isn't dead. Quite the contrary, in fact. Tinder has released data showing a dramatic rise in
...[详细]Should I put a TV in my bedroom?
Putting a TV in your bedroom seems like a good, maybe even a great, and certainly not a terribleidea
...[详细]Slack goes down again, prompting anxiety everywhere
Panic briefly took over on Tuesday when everyone's favorite messaging app/millstone went down tempor
...[详细]
The year is almost done, which feels both impossible and long overdue. 2020 was a strange 12 months,
...[详细]4 ways tech has helped my autistic son
When I heard the announcement of nursery and school closures brought on by the novel coronavirus las
...[详细]Vigorous 2020 hurricane season breaks a big storm record
Hurricane scientists expected a busy Atlantic storm season. They got one.The National Weather Servic
...[详细]Watch MTV's Video Music Awards 2016 livestream
It's MTV Video Music Awards night. Are you ready?Kanye's going to be there, and he's going to say th
...[详细]Save 15% sitewide or 20% on purchases of $300+ at Coop Home Goods.
The following content is brought to you by Mashable partners. If you buy a product featured here, we
...[详细]Make money or go to Stanford? Katie Ledecky is left with an unfair choice.

Why you shouldn’t buy Apple’s new MagSafe Duo charger
