HomeSecurityNew Snowblind malware targets Android devices

New Snowblind malware targets Android devices

The new Snowblind malware abuses a security feature to bypass existing protections on Android devices and steal sensitive data user

Snowblind malware

Snowblind's goal is to modify a target application so that it cannot detect misuse of accessibility services. This allows the malware to obtain user information, such as credentials, or gain remote access to perform malicious actions.

What makes the Snowblind malware different is that it abuses "seccomp" (secure computing), a Linux kernel that Android uses to perform checks on applications and protect users from malicious actions, such as application repackaging (which is what this malware does).

See also: Android: New Medusa banking trojan attacks

Snowblind malware: Abuse of seccomp

Security firm Promon was able to analyze how Snowblind achieves its goal without being detected.

“This malware attacked the application of an i-Sprint customer in Southeast Asia. Our analysis of Snowblind found that it uses a new technique to attack applications Android,” the company said.

Seccomp is a Linux kernel security feature designed to enhance the security of applications by restricting the system calls (syscalls) they can make. It acts as a filter for the syscalls that are allowed to be executed in an application, excluding those that have been used in attacks.

Google first integrated seccomp in Android 8 (Oreo), implementing it in the Zygote process (the parent process of all Android applications).

The Snowblind malware targets applications that handle sensitive data by injecting a native library that loads before the anti-tampering code. It installs a seccomp filter to intercept system calls, such as the "open() syscall", which is commonly used for file access.

When the target app's APK is checked for a violation, the Snowblind malware's seccomp filter prevents the call from continuing and instead triggers a SIGSYS signal, indicating that the process sent a bad argument to the system call.

See also: Singapore: Two men charged with distributing Android malware

Snowblind also installs a signal handler for SIGSYS. This way, the malware can modify the 'open()' system call arguments to direct the anti-tampering code to an unmodified version of the APK.

New Snowblind malware targets Android devices

Promon researchers say that the technique used in Snowblind attacks “ does not appear to be well-known ,” so many applications are not protected against it.

According to researchers, users don't understand anything and the Snowblind malware easily steals credentials from devices.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

Researchers told BleepingComputer that Snowblind can be used to disable various security in apps, such as two-factor authentication or biometric verification.

An attacker could use the technique “to read sensitive information displayed on the screen, navigate the device or control applications, bypass security measures, as well as steal sensitive personal information and transaction data.”

See also: Malware campaign targets Windows, Android and macOS

Snowblind malware is just one of many emerging Android attack vectors that highlight the need for users and developers to remain vigilant against evolving threats cyber. By understanding how these attacks work and taking proactive steps to protect personal devices, we can mitigate the impact of such malicious activities. As technology continues to advance, it is important to stay informed and take the necessary precautions to protect our digital lives. So, being aware of new threats like Snowblind can go a long way in keeping our devices and data safe.

Source: www.bleepingcomputer.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS