HomeSecuritySharp increase in malicious attacks on Android devices

Sharp increase in malicious attacks on Android devices

Increase in the number of Trojan-SMS malware attacks
Kaspersky Lab researchers observed a significant increase in the number of Trojan-SMS malware attacks in the second half of the year

The number of financial malware attacks against users of Android devices increased by 3.25 times in 2014, according to a Kaspersky Lab study titled “Financial Cyberthreats in 2014.”

Kaspersky Lab researchers observed a significant increase in the number of Trojan-SMS malware attacks in the second half of the year

Specifically, 48.15% of attacks against Android, which were blocked by Kaspersky Lab products, used malware targeting financial data (Trojan-SMS and Trojan-Banker).

Furthermore, the number of financial attacks against Android users in 2014 increased by 3.25 times compared to 2013 (from 711,993 to 2,317,194 attacks), while the number of users attacked increased by 3.64 times (from 212,890 to 775,887).

The research also showed that 98.02% of all Android banking malware corresponded to just three malware “families.”

Android is one of the most popular mobile operating systems in the world. As such, it attracts cybercriminals who target users’ personal information and money. In 2014, Kaspersky Lab’s products for Android devices prevented a total of 2,317,194 financial attacks against 775,887 users worldwide.

Most of them (2,217,979 attacks against 750,327 users) used Trojan-SMS malware, while the rest (99,215 attacks against 59,200 users) used Trojan-Banker malware.

Although the contribution of Trojan-Bankers to the overall volume of financial attacks against Android users is relatively small, it continues to grow. During the year, Kaspersky Lab products detected 20 different Trojan-Banker malware.

Among them there were only three main "protagonists": Faketoken, Svpeng and Marcher.

Svpeng and Marcher are capable of stealing login details to online banking accounts, as well as credit card details, by replacing bank account identification fields on an “infected” device.

Faketoken is designed to steal mTAN codes, which are used in multi-factor authentication systems, and forward them to criminals. These three “families” accounted for 98.02% of all Trojan-Banker attacks.

According to the announcement, in the spring of 2014, Kaspersky Lab researchers noticed a significant decrease in the number of Trojan-SMS malware attacks. A possible reason for this decrease was the introduction by mobile operators in Russia (the main source of the Trojan-SMS threat) of the “Advice of Charge” service. This means that every time a customer (or a Trojan-SMS) attempts to send a message to a premium rate number, the operator notifies the customer how much the service will cost and requests additional confirmation from the user.

The downward trend stopped in July and was followed by a steady increase for the rest of the year. The increase accelerated in December, which is traditionally a month of particularly high online shopping and transactions, with criminals targeting financial data.

“During 2014, our cumulative database of Android users grew significantly, which led to an increase in the number of financial malware detections and the number of users who fell victim to them. However, the overall growth rate of financial malware attacks was faster and greater than could be explained by the increase in the number of Android devices alone. This growth rate is mainly due to Trojan-SMS. We believe that the main reason for the return of Trojan-SMS is the emergence of malware that is capable of both “infection” and theft, even when the “Billing Information” service is implemented in the mobile network. For example, we discovered such functionality in malicious modifications of the Opfake.a and Fakeinst malware. Both are very active representatives of Trojan-SMS,” said Roman Unuchek, Chief Malware Analyst at Kaspersky Lab.

Source: protothema.gr

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SecNews
SecNewshttps://www.secnews.gr
In a world without fences and walls, who needs Gates and Windows

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS