HomeSecurityBaidu Browser acts like a mild form of Tempered Infostealer virus

Baidu Browser acts like a mild form of Tempered Infostealer virus

Baidu Web browser for Windows and Android exhibits behavior that could easily allow a security researcher to classify it as an infostealer virus, because it collects information about its users and then sends it to Baidu's home servers.

Baidu Browser is the Chinese clone of Google Chrome, with Baidu being a Web search company in China, just like Google, and the browser a spin-off from the Chromium project, just like Google Chrome.

baidu browser

According to researchers at Citizen Lab, the browser engages in the now-obligatory habit of collecting user data, which many software and Web-based services do, “serving analytics purposes.”

The problem is that the Baidu browser collects and then sends this information over unencrypted or easily decrypted connections.

During tests, researchers say the Android collects data about the user's operating system, the phone's IMEI (International Mobile Station Equipment Identity), browsing history, search terms history, the phone's latest GPS coordinates, nearby wireless networks, and local Macs.

On the other hand, the Windows also collects data such as the user's search history, browsing history, MAC address, CPU model, hard drive model, and serial number and file system version number.

The browser collects and sends this information at startup, when the user begins typing content into their address bar, and on each page view.

Obviously, this is an invasion of the user's privacy and involves something that one would not expect browser . This same behavior is often found in infostealer (information stealer) malware that is usually developed to collect information about targets before deploying more complex threats such as ransomware, Bitcoin miners, spyware or banking trojans.

Citizen Lab researchers narrowed down the information leakage issues to a common SDK, Baidu Mobile Tongji (Analytics) SDK, used for both Android and Windows versions.

Together with mobile security firm Lookout, researchers detected this SDK inside 22,548 app packages. Back in November 2015, researchers from Trend Micro had detected similar Baidu SDKs, which could be found in 14,112 Android apps and included features that could be abused to install backdoors on all infected systems.

But Baidu Browser's issues didn't stop there. Researchers also discovered that the browser's checks and update downloads don't use code signatures. This practice exposes users to MITM (Man-in-the-Middle) attacks that allow an attacker to send malicious files to users disguised as a Baidu update.

MITM (Man-in-the-Middle) attack

The researchers say they informed Baidu of all of their issues, and they began addressing them through updates for both the Android and Windows versions on February 14, 2016. However, some information leakage still exists.

Baidu agreed to answer a list of questions about browser behavior. You can see those answers here.

In May 2015, the same Citizen Lab researchers analyzed another Chinese web browser (UC Browser) and found a plethora of issues in that product as well.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS