Researchers have discovered a new malware campaign for Android phones that does not require any kind of user interaction in order to infect devices with ransomware.
The infection occurs when users visit a website that contains malicious JavaScript. Blue Coat Labs says the malicious code is delivered via malicious ads (malvertising).
Security researchers from Zimperium have confirmed that the malicious code contained an exploit that was leaked last year in the Hacking Team data breach.
The exploit exploits a vulnerability in Android's libxslt library to allow hackers to download a Linux ELF binary named module.so to the device.
This binary uses the Towelroot Android exploit (the name of a rooting tookit) to gain root access on the device. Once root access is secured, module.so will also download an additional Android APK, which contains ransomware code.
With root access in hand, the attacker can silently install the ransomware without asking the user for any permissions.
The name of this ransomware trojan is Cyber.Police and it was first detected in December 2014. Compared to desktop-based ransomware that encrypts files, Cyber.Police only locks the user's screen and asks them to purchase two Apple iTunes gift cards worth $100 each.
Even though Apple registers iTunes gift cards, they can be used as virtual currency in the underground hacking and pass from hand to hand for years by many people before being used.
Blue Coat Labs says that infected victims sent unencrypted traffic from their device to a central command and control server. The company was able to monitor traffic originating from 224 different Android device models (tablets, smartphones), using Android versions between 4.0.3 and 4.4.4.
The lowest officially supported version of Android is 4.4.4, which means attackers are targeting users who have failed or are unable to upgrade their devices.
“The fact that some of these devices are known not to be vulnerable specifically to the Hacking Team libxlst exploit means that different exploits may have been used to infect some of these [other] mobile devices,” notes Blue Coat’s Andrew Brandt.
So, in case you are infected with the Cyber.Police Android ransomware, Blue Coat says it will be able to remove the malware after resetting the device to its factory settings.
Before performing a factory reset, users should connect the device to their computer and copy their personal data to the computer.
Upgrading to a newer version of Android does not help, because Cyber.Police was installed as a regular app and Android updates keep apps intact during the upgrade.



