Security researchers are warning about an advanced variant of the NotCompatible trojan, which targets and infects Android.
According to experts, the communications infrastructure on which Notcompatible relies is the most complex ever identified for mobile devices, while the technology it relies on is so sophisticated that it rivals that of similar malware designed for desktops. In fact, the latest variant of the malware is so advanced that it poses a threat even to protected corporate networks.
The main method used by cybercriminals to distribute malware is social engineering.Through spam campaigns, but also through drive-by download attacks (which are carried out with the help of compromised websites), criminals lure unsuspecting users into installing NotCompatible on their devices.
According to a sample of emails identified by researchers, it appears that potential victims are asked to install a security update in order to gain access to an attached file.
Lookout researchers have been tracking the Trojan since 2012, when it was first used as a proxy on infected devices to carry out spam campaigns. However, the latest variant of NotCompatible relies on sophisticated peer-to-peer communication, encryption, and a server architecture that makes it “elusive and persistent.”.
"NotCompatible.C uses a two-tier server architecture. The command and control (C&C) server uses a load balancing approach, whereby infected devices from different IP addresses are filtered and geographically fragmented, and only authenticated clients are allowed to connect," Lookout researcher Tim Strazzere said in a blog post.
According to Lookout, there are over ten central C2 servers serving Notcompatible, operating in different countries, such as Sweden, Poland, the Netherlands, the United Kingdom, and the United States. From analyzing the botnet's activity, researchers have concluded that NotCompatible is rented to carry out various malicious campaigns, such as spam delivery, brute-force attacks against WordPress log-in pages, and control of other malicious programs (e.g. c99shell – a PHP shell script that provides access to the victim's system).
NotCompatible is also the perfect tool for carrying out attacks against corporate networks, as it is difficult to detect and block by network security systems.
"Once a device infected with NotCompatible.C enters an organization's network, it can be used to provide botnet operators with access to the organization's network. Using NotCompatible as a proxy, an attacker could potentially locate vulnerable hosts within the network, exploit vulnerabilities, and search for exposed, sensitive data," Lookout researchers explain.
📧
Subscribe to the SecNews Newsletter

