Gunpoder: Nintendo fans with Android devices should be extra careful. A new malware for the Android platform has appeared on third-party App Stores disguised as a classic Nintendo game.
Security firm Palo Alto Networks says it has discovered a new family of malware that looks and behaves like adware while stealing personal information from infected Android devices. The malware is called Gunpoder, and it is hidden in a game.
The app is based on an open-source Nintendo Entertainment System emulator (an app that runs classic Nintendo games from the 1980s on mobile) and is available in third-party App Stores.
The developers of the Gunpoder malware modified the original emulator and added a payment function, and a feature that gives the game access to the device's contact list . The result is a paid app that steals your personal information.
How it works:
After downloading, the malicious Gunpoder app informs users with a message that the emulator is ad-supported. By tapping “OK,” you agree to let a program called Airpush collect data from your device.
Airpush is a library commonly used to push ads to mobile devices. Inside this NES emulator, however, it gathers a lot of personal data from a device, including the user's location, contact list, website bookmarks, and information about the device itself.
"They're trying to create an accurate profile of the people using the app so they can target them with spearphishing or other malicious activities in the future," says Scott Simkin, senior director at Palo Alto Networks.
In addition to being able to collect information from users for future attacks, Simkin says the hacker can also sell it on various forums.
When users agree to have their data collected, the app displays another notification asking users to purchase a license. If users agree, the app collects payment information and charges them $0.45 for the license.
Palo Alto Networks says that using Airpush allows Gunpoder to evade detection by antivirus software. Most antivirus software does not block or detect such adware.
[alert variation=”alert-info”]In addition to being undetectable by antivirus software, the malware has mechanisms for spreading. The supposed NES game asks users who have installed it to share the news with their contacts via SMS, thus infecting a whole new generation of Android devices.[/alert]
Palo Alto Networks says it found 49 unique samples of the malware that may have been developed in different countries including: the US, Iraq, Thailand, India, Indonesia, South Africa, Russia, France, Mexico, Brazil, Saudi Arabia, Italy, and Spain.
Simkin says Palo Alto Networks customers are now safe from this type of malware. However, consumers in general are not. In order to stop the spread of Gunpoder, users should avoid downloading applications fromthird-party websites.
source: iguru


