Adware Programs 'Masquerade' as Popular Apps, and Root Android Devices
Android adware
Mobile security firm Lookout has identified thousands of samples of malicious adware masquerading as legitimate applications.
Over the past year, a trio of Android adware programs have posed as popular apps and then, after users install them on their devices, took complete control of them, according to a report published by mobile security firm Lookout.
The three adware programs—known as Shedun, Shuanet, and ShiftyBug—are interconnected families whose developers reportedly share the same code. While adware—and other potentially unwanted programs—are a familiar headache for Android users, the three programs in question have become much more malicious, masquerading as popular apps—such as Candy Crush and Facebook. When the program runs, it installs the app and simultaneously takes control of the device and installs adware.
In the past year, adware programs have counted more than 20,000 malware samples, each packaged differently but always as a legitimate app, according to Lookout. Anyone who installs the apps will soon find their device rooted, says Michael Bentley, Lookout's head of research.
“About 30 seconds after you install this popular, seemingly legitimate app on your device, the application will install all of its components into the system directory,” Bentley says. “Other apps don’t have access to remove code from the system directory, so the malware takes full ownership of the victim’s device.”

