Dvmap Trojan: Kaspersky Lab experts have discovered an unusual new Trojan distributed via the Google Play Store. The Dvmap Trojan is able not only to gain full root access to Android smartphones, but can also take control of the device by injecting malicious code into the system library. If successful, it can then revoke full access, which helps to avoid detection.
The Trojan has been downloaded from Google Play more than 50,000 times since March 2017. Kaspersky Lab reported the Trojan to Google and it has now been removed from the store.
Gaining the ability to inject code is a dangerous new development in mobile malware. Since the approach can be used to perform malicious operations even with full access removed, any security solutions and banking apps with full detection capabilities installed after the “infection” will not detect the presence of the malware.
However, modifying system libraries is a risky process that can backfire. Researchers observed that the Dvmap malware tracks and reports its every move to the command and control server – even though the command server did not respond with instructions. This suggests that the malware is not yet fully ready or implemented.
Dvmap is distributed as a game through the Google Play Store. To bypass the store’s security checks, the malware’s creators “uploaded” a “clean” app to the store in late March 2017. They then updated it with a malicious version for a short period of time, before “uploading” another clean version. They did this at least five times over a four-week period.
The Dvmap Trojan installs itself on the victim’s device in two stages. During the initial phase, the malware attempts to gain full root privileges on the device. If successful, it will install a series of tools, some of which contain comments in Chinese. One of these modules is an application, “com.qualcmm.timeservices”, which connects the Trojan to the command and control server. However, during the period of investigation, the malware did not receive any commands back.
In the main phase of the “infection”, the Trojan launches a “boot” file, checks the version of Android installed and decides which library to inject its code into. The next step: replacing the existing code with malicious code, which can cause the “infected” device to crash.
The newly updated system libraries run a malicious module that can disable the “App Verification” feature. It then enables the “Unknown Sources” setting, which allows it to install apps from anywhere, not just the Google Play Store. These could be malicious or unwanted adware.
“The Dvmap Trojan marks a dangerous new development in Android malware, with malicious code being inserted into system libraries where it is harder to detect and remove. Users who do not have the necessary security to detect and block the threat before it spreads will have a hard time. We believe we have uncovered the malware at a very early stage. Our analysis shows that the malicious modules report their every move to the attackers, and certain techniques can break into “infected” devices. Time is of the essence when it comes to preventing a massive and dangerous attack,” said Roman Unuchek, Senior Malware Analyst at Kaspersky Lab.
Concerned users who may have been infected by Dvmap are advised to back up all their data and perform a factory data reset. In addition, Kaspersky Lab advises all users to always check that applications are created by a trusted developer, keep their operating system and application software up to date, and not download anything that looks suspicious or whose source cannot be verified.
All Kaspersky Lab products detect the Trojan as Trojan.AndroidOS.Dvmap.a.
