Mobile Trojans were declared the winners last year. In 2016, there was an almost threefold increase in mobile malware detections compared to 2015. Specifically, a total of 8.5 million malicious installations were detected. This means that in just one year, a volume corresponding to 50% of all malware detected in the previous 11 years (15.77 million in the period 2004-2015) was released.
Leading the way were mobile advertising Trojans , which now make up 16 of the top 20 malware, up from 12 in 2015. These are the findings of Kaspersky Lab titled “Mobile Virusology,” which also highlights the evolution of Trojans in the mobile banking. Specialists from the Interpol Global Complex for Innovation (IGCI) contributed to the report with an analysis of mobile malware found on the Dark Web.
In 2016, Kaspersky Lab's mobile security products reported:
- Approximately 40 million mobile malware attack attempts, with over 4 million Android users protected (compared to 2.6 million in 2015)
- Over 260,000 mobile ransomware Trojans installation packages detected (an increase of almost 8.5 times, year-on-year)
- More than 153,000 unique users were targeted by mobile ransomware (a 1.6x increase compared to 2015)
- Over 128,000 mobile banking Trojans detected (about 1.6 times more than in 2015)
Advertising Trojans: have they already rooted your device?
- The most prevalent Trojan types in 2016 were in the form of advertisements, accounting for 16 of the top 20 malware
These Trojans are able to remove basic rooting privileges, allowing the malware not only to aggressively display ads on infected devices, often rendering them unusable, but also to secretly install other apps. These Trojans were also able to purchase apps on Google Play.
In many cases, Trojans were able to exploit previously patched vulnerabilities because users had not installed the latest updates.
Furthermore, this malware simultaneously installs its extensions into the system directory, which makes it quite difficult to treat the infected device. Some adware Trojans have the ability to infect the recovery image, making it impossible to fix the problem even with a factory reset.
Offshoots of this malware category have been repeatedly found in the official Google Play app store, such as a disguised guide for Pokémon GO. In this case, the specific application was downloaded more than 500,000 times and is identified as Trojan.AndroidOS.Ztorg.ad.
Mobile ransomware programs: further increase
- 167 countries were attacked with Trojan-Ransom, a size increased by 1.6 times compared to 2015.
- In 2016, 153,258 unique users from 167 countries were attacked by Trojan-Ransom programs. This number is 1.6 times higher compared to 2015.
Modern ransomware overlays the windows the user is working on with demanding messages, making the device unusable. This element was used by the most famous ransomware in 2016 – Trojan-Ransom.AndroidOS.Fusob.
This Trojan mainly attacks users in Germany, the United States and the United Kingdom, but avoids users in Russia and some neighboring countries. Once launched, it runs a check on the device's language and then, after checking the results, may stop the execution of the process. The cybercriminals behind these Trojans ask for between $100 and $200 to unlock a device. Payment can only be made using prepaid iTunes cards. king Trojan: a flying threat
- In 2016, over 305,000 users in 164 countries were attacked by mobile banking Trojans, compared to over 56,000 users in 137 countries the previous year.
- Russia, Australia and Ukraine are the top 3 countries in the ranking that were attacked, based on the percentage of users attacked by mobile banking Trojans compared to users who have fallen victim to mobile malware overall.
Mobile banking Trojans have continued to evolve over time. Many of them have acquired tools to bypass new Android security mechanisms and were able to continue stealing user information from the latest versions of the operating system. At the same time, developers of mobile banking Trojans have repeatedly enhanced their creations with new capabilities. For example, the Marcher “family”, in addition to the usual overlay of banking applications, often redirects users from financial institution websites to phishing sites. The Dark Web Deception
According to Interpol Global Complex for Innovation (IGCI) experts, who also contributed to the report, the Dark Web remains an attractive medium for conducting illicit business and activities. Given its strong anonymity, low prices and customer-centric strategy, the Dark Web provides a means for criminal actors to communicate and engage in commercial transactions, buying and selling various products and services, including mobile malware. Mobile malware is offered for sale as software packages (e.g. remote access Trojans – RATs), individual solutions and sophisticated tools, such as those developed by professionals or, on a smaller scale, as part of a “Bot as a Service” model. Mobile malware is also an “object of interest” for vendor stores, forums and social media.
“In 2016, the number of adware Trojans capable of exploiting super-user. Throughout the year, it was the top threat and we see no sign of this trend changing. Cybercriminals are taking advantage of the fact that most devices do not receive operating system updates (or receive them when it is already too late), and are therefore vulnerable to old, known and readily available exploits. In addition, we see that the mobile landscape is becoming “suffocating” for cybercriminals and they are starting to interact more with the world beyond smartphones. Perhaps in 2017 we will see large-scale attacks on IoT components, which will be launched from mobile devices,” concludes Roman Unuchek, Senior Malware Analyst at Kaspersky Lab USA.
