HomeSecurityTrojan found pre-installed on Android devices

Trojan found pre-installed on Android devices

TrojanTrojan found pre-installed on Oysters T104 HVi

A virus targeting Android was revealed by Dr. Web – a Russian antivirus company – to be pre-installed in the firmware of some Android devices.

The virus was detected as Android.Backdoor.114.originin mid-September, and after Dr. Web contacted the device manufacturers, no changes were made to the malicious firmware, which is still available online for download.

oysters

According to company personnel, the malware was detected inside the Oyster T104 HVi 3G Smartphone, which was located inside the GoogleQuickSearchBox.apk application, and comes pre-installed on the device.

The Trojan is somewhat dangerous and comes with administrator privileges on infected smartphones and sends the user's data to the attackers.

Its main role is to «communicate» with a C&C server. It can therefore collect and send information and data to its owners.

3

Once this information reaches the C&C server, the attackers send additional commands, based on the collected data, in order to carry out attacks specially crafted for the specific user.

The virus is therefore a "gateway" for more malicious malware.

Most of the time these instructions «tell» the device to hijack other applications, which can be used to serve unwanted ads, or even worse, to lock the device, encrypt the files and demand ransom.

Because it comes pre-installed, the only way to get rid of it is to reinstall a clean version of the operating system.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS