Android remains at number one Operating System worldwide so also getting targeted by Malware creators.
In 2013 about 98 percent of all malware detected were targeted android platform making it as a prime target for malicious attacks.
Various techniques are being used to target android users. Spammers are using phishing technique to spread android malwares. Mobile Antivirus companies and their research labs are reporting several variants of android malwares.
SandroRAT is a new android malware variant of RAT (remote access trojan). Recently attackers spread SandroRAT using phishing techniques to target victim by sending email with subject like
“Caution! Detected malware on your phone!”
And having download link or attached apk of malware with mail. The sample received by McAfee Labs from customer in Poland with the name Kaspersky_Mobile_Security.apk Phishing mail with following attachment:
The body of the message states that the bank is providing the attached free mobile security application to detect malware that steals SMS codes (mTANs) for authorizing electronic transactions. However, the attached application is in fact a version of the Android RAT SandroRat, which was announced at the end of the last year in the Hacking Community HackForums. The RAT and its source code are for sale, making it accessible to everyone to create a custom version of this malware.
SandroRAT malware has functionality to decrypt WhatsApp encrypted chats, latest version of WhatsApp uses encryption scheme (crypt 7) so decryption routines of malware will not work with latest version of WhatsApp. WhatsApp user should update the app to latest version.
Source: McAfee
Varutra has developed a mobile application for checking vulnerabilities on the mobile operating system of your smartphone. Access the MVD application from https://www.varutra.com/mvd/ or download MVD app android version from Google Play.
Author: Snehal Raut
Security Consultant,
Varutra Consulting
Introduction In an increasingly interconnected world, the financial industry is becoming more vulnerable to cyber…
Introduction In today's interconnected world, where smartphones are an extension of our lives, ensuring the…
Introduction Unseen and unpredictable, zero-day threats loom as a constant menace to modern businesses. Detecting…
Android penetration testing is a crucial aspect of ensuring the security of Android applications and…
In today's interconnected world, where cybersecurity is of paramount importance, password security plays a crucial…
Introduction to Web & Mobile Application Security Assessment Web and Mobile applications have become an…
View Comments
Hi! I discovered your website accidentally this morning, but am really pleased which i did! Its not only entertaining, but also straightforward to make use of compared with lots that Ive viewed!
I simply want to mention I am very new to blogging and site-building and really liked this web blog. Very likely I’m likely to bookmark your blog . You actually come with good writings. Appreciate it for sharing with us your blog site.
Thanks for sharing the valuable information.love the blog. very interesting. sincerly, Tomasz Michałowski
I like what you guys are up also. Such clever work and reporting! Keep up the superb works guys I've incorporated you guys to my blogroll. I think itll improve the value of my site :))
Thank you :)
You made a number of nice points there. I did a search on the matter and found nearly all persons will have the same opinion with your blog... Have you considered promoting your blog? add it to SEO Directory right now :)
Im still learning from you, while Im making my way to the top as well. I absolutely enjoy reading all that is posted on your site.Keep the stories coming. I liked it!
Thank You :)
Excellent read, I simply passed this onto a colleague who was doing a little analysis on that. And he truly purchased me lunch as a result of I found it for him smile So let me rephrase that: Thanks for lunch! Anyway, in my language, there should not a lot good source like this.
I have been browsing online more than three hours today, yet I never
found any interesting article like yours. It's pretty worth enough for
me. Personally, if all web owners and bloggers made good content as you
did, the net will be a lot more useful than ever before.