A new Android Trojan that appears to be the first Android Bootkit has been detected by Russian security firm Doctor Web.
The malware is placed in the memory of infected devices and begins its operation at the OS loading stage, which makes it difficult to remove from the device.
The trojan, called Android.Oldboot.1.origin, installs one of its components in the boot point of the file system. It also modifies the init script – a specialized program for initializing Android system components.
When the device is turned on, the script runs and installs other malware components as a standard application.
Virus that cannot be removed with Antivirus :
This malware is considered the most dangerous of Android malware because even if you remove it, when the device reboots, the item present in the protected area of memory will re-infect the device.
Researchers believe that the threat enters the device when the user installs the modified firmware containing this Trojan on their smartphone.
The malware appears to have infected over 350,000 mobile devices. 92% of the infected devices appear to be from China.
To prevent such a threat, make sure not to install firmware from untrusted sources. Users should also avoid purchasing devices of unknown origin.

