Security researchers from Doctor Web have discovered what they believe is the first Android bootkit. The threat has already infected 350,000 devices worldwide.
The Trojan, dubbed Android.Oldboot.1.origin, uses some clever techniques to ensure that it cannot be easily removed. A component of it is installed in the system's boot partition.
The file modifies the device's boot process, loading the Android.Oldboot components with a script. Once Android.Oldboot is installed on a device, the trojan connects to a remote server and waits for commands.
“When the mobile phone is turned on, this script loads the code of the Trojan Linux-library imei_chk (the Dr.Web Anti-virus detects it as Android.Oldboot.1), which extracts the files libgooglekernel.so (Android.Oldboot . 2) and GoogleKernel.apk (Android.Oldboot.1.origin) and places them in the paths /system/lib and /system/app, respectively,” the researchers report.
“Thus, part of the Android.Oldboot Trojan installs itself as a standard application, which runs as a system service and uses the libgooglekernel.so library to connect to a remote server and receive various commands, mainly to download, install or remove certain applications.”
The problem is that even if it is removed, when the device reboots the Trojan follows the same process, since it is located in the protected area of memory.
Experts believe that the malware is distributed with the help of some modified firmware. When users root their smartphones and install this firmware, they do not actually know what is running on their device.
Most infections with this malware (92%) have been detected in China, which seems to be its main target. However, infected devices have also been observed in Germany, Spain, Russia, Italy, the US, Brazil and other countries from Southeast Asia.
The best way to protect your smartphone is to avoid installing firmware from untrusted sources.

