SpyDealer: A newly discovered Android malware can steal data from over 40 popular apps, including Facebook, WhatsApp, Skype, and Firefox. The malware has reportedly been actively engaged in this illegal activity for nearly two years.
Dubbed SpyDealer by Palo Alto Networks researchers who discovered it, it allegedly collects accounts and personal data from its victims. The data includes phone numbers, messages, contacts, call history, information from Wi-Fi connections, and even the device's geographic location.
The malware allows crooks to record phone calls, video, and audio, take photos with the front and rear cameras, and even take screenshots of sensitive information.
Described as a highly advanced form of Android malware , SpyDealer is able to open a backdoor on devices, exploiting a commercially available Android application to root the victim device and gain root privileges.
Samples of the malware analyzed by the researchers suggest that the malware reuses root exploits used by the commercial application “Baidu Easy Root” to gain root privileges.
SpyDealer is able to receive instructions from a command and control server – as well as commands via text messages, which allows crooks to remotely control the infected device.
SpyDealer is fully effective on Android devices from versions 2.2 to 4.4 as the root tool it uses only supports these versions of the mobile operating system.
Even though these versions of Android are ancient – Android 2.2 was first released in May 2010 and Android 4.4 was released in late 2013 – researchers report that a quarter of Android devices are still running these versions.
So with two billion active Android devices, that means 500 million Android devices are vulnerable to this malware.
Researchers are unsure how devices are infected with SpyDealer, but evidence suggests that Chinese users are infected via hacked wireless networks.
It should also be mentioned that those behind SpyDealer have been collecting data and accounts for over a year and a half, since the oldest sample of the malware dates back to October 2015.
Palo Alto Networks has already reported the threat to Google, which immediately created new protections through Google Play Protect.
According to researchers, SpyDealer attempts to steal data from the following applications: WeChat, Facebook, WhatsApp, Skype, Line, Viber, QQ, Tango, Telegram, Sina Weibo, Tencent Weibo, Android Native Browser, Firefox Browser, NetEase Mail, Taobao, and Baidu Net Disk.
