Two months ago, the first widespread version of an Android Bootkit malware, dubbed “Oldboot.A,” was reported. The malware has infected over 500,000 Android smartphones over the past eight months, primarily in China.
This malware for the Android platform is designed to repeatedly infect phones, even after careful cleaning. It typically resides in the memory of infected devices, modifies the boot partition, and starts running malicious applications during the early phase of system startup.
But a new, alarming report on smart malware has been released by Chinese security firm “360 Mobile Security.” Researchers have discovered a new variant of the oldboot family, which they have named “Oldboot.B,” and it is designed exactly like its predecessor (version A), but the new variant appears to use obfuscation techniques that make it nearly invisible.
The Android Bootkit malware has the following capabilities:
- It can silently install malicious applications in the background.
- It can run malicious modules in system processes.
- Can avoid uninstallation.
- Oldboot.B can modify the browser's home page.
- It has the ability to uninstall or disable installed Mobile Antivirus software.
Once an Android device is infected with this trojan, it will connect to the command and control center to receive orders from the attacker or attackers.
After installation, the Trojan will install several other malicious Android apps or games on the infected device, according to THN.
The architecture of Oldboot.B includes four core features, those that it executes automatically during system startup, registering itself as a system service within the init.rc script:

1) boot_tst – uses remote injection technique to pass an AA file and a JAR file to the Android system “system_server” process, constantly monitoring sockets, to execute the commands sent.
2) adb_server – replaces the Android system pm script with itself and will be used to prevent the uninstallation of malware.
3) meta_chk – updates the configuration file, downloads and installs Android Apps in the background. The configuration file is encrypted, which significantly increases the time required to analyze it.
To avoid detection the attackers have configured meta_chk to self-destruct from the file system, and they use it only for the injection process. Security mechanisms for Android do not support memory scanning on the Android platform, and therefore cannot detect or delete the oldboot Trojan that is there.
4) agentsysline – written in the C++ programming language, it runs as a daemon in the background to receive commands from the command and control server. This component can uninstall anti-virus software, delete specific files, and enable or disable network connection, etc.

