HomeSecurityAndroid certificates are used for malware

Android certificates are used for malware

Many of the certificates that Android OEM device vendors use to digitally sign their core applications have also been used to sign malicious Android applications.

See also: Schoolyard Bully Android malware: Steals Facebook accounts

Android certificates

Android device manufacturers use platform certificates, or keys, to sign the ROM images that contain Android applications and the operating system.

If an application, even a malicious one, is signed with the same platform certificate and assigned the highly privileged user ID ' android.uid.system ', it will also gain system-level access to the Android device

With these permissions, apps can interact with calls, install and uninstall packages, collect device information , and perform other highly sensitive actions.

A now-public report to the Android Partner Vulnerability Initiative (AVPI) shared this misuse of platform keys discovered by Łukasz Siewierski, a Reverse Engineer on Google's Android security team.

A search on VirusTotal discovered that some of the certificates associated with the platforms being misused belong to Samsung Electronics, LG Electronics, Revoview, and Mediatek.

See also: Microsoft Teams for Android gets live transcription feature

At this time we cannot determine who the other certificates belong to.

malware

Malware that uses Android certificates for authentication includes some such as HiddenAd trojans, information stealers, Metasploit, and malware droppers. This malware allows attackers to deliver additional payloads to compromised devices

Google , and keep the number of apps signed with Android certificates low to avoid future problems.

Google has notified all parties of the issue and recommended workarounds, but it appears that not all companies have acted on the company's advice. In Samsung's case, it is still using leaked platform certificates to sign apps.

See also: Android and iOS lending apps trapped borrowers

Android malware is a type of malware designed to target Android devices. These devices are particularly vulnerable to malware due to their open-source nature and the fact that they can be easily rooted. Malware can be used to gain access to sensitive information, such as passwords and credit card numbers, or it can be used to cause damage to the device or its data. There are many different types of Android malware, and new strains are constantly being created.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr
Being your self, in a world that constantly tries to change you, is your greatest achievement

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS