HomeSecurityChinese marketing company distributes adware to promote apps

Chinese marketing company distributes adware to promote apps

A Chinese company that advertises itself as a mobile app advertiser has been deceiving its customers by developing adware to install its apps on unsuspecting victims.
The company, called NGE Mobi/Xinyinhe, with operations in China and Singapore, used popular apps, repackaging them with malicious adware code, which is distributed through unofficial Android app stores.
When users install these apps on their smartphones, the adware comes to life, collects information about the device, sends it to a C&C server, and then waits for new commands.
When the server responds, the app continues by installing a root backdoor and a series of daemons that allow it to survive system reboots.
This is where the fun begins, because once the adware has been firmly "implanted" on the victim's phone, it starts serving specific apps and ads, all from the NGE Mobi/Xinyinhe.

As FireEye found in its research, most often pornographic applications and interstitial ads appear on the user’s home screen, all of which are harmless but very annoying. At the moment, the adware has been found on Android versions ranging from version 2.3.4 to 5.1.1. with the most infected users being in countries such as Russia, China, Brazil, Argentina, Egypt, Spain, France, Germany, Sweden, Norway, Saudi Arabia, Indonesia, India, the United Kingdom, and the United States. The NGE adware campaign was first observed in August and has been evolving at a steady pace since then. Worst of all, FireEye researchers point out, is that the adware’s creators were extremely careless when they put together the malicious code. Because the C&C server communications are done over blind HTTP channels, a second attacker could easily intercept these transmissions. Once the adware gained root privileges and booted with the device on all infected devices, another attacker could use this advantage to serve much more dangerous applications compared to mindless adult apps and advertisements. The first example that comes to mind is when the second attacker adds the infected phones to a botnet and uses them to carry out DDOS attacks . Even worse scenarios are when the attackers decide to spy on your personal photos or install ransomware on your phone.Chinese marketing company distributes adware to promote apps






📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS