HomeSecurityAndroid Malware "Godless" Found on Google Play Store

Android Malware “Godless” Found on Google Play Store

Godless, detected by Trend Micro as ANDROIDOS_GODLESS.HRX, is a malware family affecting Android smartphones and tablets that leverages rooting exploits to escalate its access to the administrator's device.

Trend Micro says the app is distributed through different methods and from multiple locations, including through Google, which is usually considered a safe option for downloading apps.

Android Malware "Godless" Found on Google Play Store

Godless resides within various applications and when allowed to run, it will download the android-rooting-tools project from GitHub, which is a collection of open-source or leaked exploits to root Android devices.

Based on the source code it analyzed, Trend Micro says that Godless can root all Android versions, starting with Android Lollipop (5.1) and back. Based on its portfolio of rooting exploits, Godless could theoretically root 90 percent of all Android devices currently available.

The most powerful rooting exploits found in Godless' collection of hacking tools include CVE-2015-3636 (PingPongRoot exploit) and CVE-2014 – 3153 (Towelroot exploit).

When Godless is infected, it runs applications and then ends up downloading rooting exploits, the malware will make sure that the user's screen is off and then execute the malicious code.

After Goodless gains root privileges, it begins communicating with a C&C server, from where it gets a list of applications to install on the rooted device.

In previous versions of the malware observed a few months earlier, Trend Micro researchers say Goodless was used to download a clone of the official Google Play Store, which would be used to collect the user's Google credentials.

With these credentials in hand, Goodless would then download and install other apps using Google's official Play Store app.

The security firm estimates that Goodless has at least 850,000 victims worldwide. Based on the graphic below, the most users are in India (46.19 percent), followed by Indonesia (10.27 percent) and Thailand (9.47 percent).

godless-graphic

At the beginning of May, Bitdefender discovered a similar Android malware that is also used for rooting exploits.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS