Sockbot: Many applications on Google Play have been infected with malware from time to time, and security company Symantec is warning about yet another malware that appears to have been installed on at least 600,000 devices.
The reason for Sockbot, which creates a SOCKS proxy on each device and waits for the author's commands.
Symantec says that although the primary goal of the apps was to generate revenue from ads, the malware can very easily turn an infected device into a member of a botnet that even enables DDoS attacks.
Two apps on Google Play have already been confirmed to be infected with Sockbot, which have since been removed. It is estimated that between 600,000 and 2.6 million devices have downloaded the infected apps.
Targeting users in the United States, Russia, Ukraine, Brazil, and Germany, the malware was injected into apps offering skins for Minecraft: Pocket Edition (PE) and was developed by an account called FunBaster.
The malicious code is obfuscated and key strings are encrypted, preventing basic forms of detection. Additionally, the developer signs each application with a different developer key, which helps avoid static analysis.
Once an Android device is infected with Sockbot, the malware connects to a command and control (C&C) server on port 9001 to receive commands, and in most cases what it retrieves is a list of ads and related metadata such as name and screen size.
Android users who have already installed such an app are advised to remove it as soon as possible, if Google has not already done so.
