{"id":25532,"date":"2018-05-15T13:04:38","date_gmt":"2018-05-15T12:04:38","guid":{"rendered":"http:\/\/www.intelligentcio.com\/me\/?p=25532"},"modified":"2018-05-21T11:20:13","modified_gmt":"2018-05-21T10:20:13","slug":"the-tricks-cybercriminals-are-using-to-hide-in-your-phone","status":"publish","type":"post","link":"https:\/\/www.intelligentcio.com\/me\/2018\/05\/15\/the-tricks-cybercriminals-are-using-to-hide-in-your-phone\/","title":{"rendered":"The tricks cybercriminals are using to hide in your phone"},"content":{"rendered":"<p>&nbsp;<\/p>\n<p><em>Malware in the official Google store never stops appearing \u2013 it is a \u2018huge victory\u2019 for cybercriminals to sneak their malicious applications into the marketplace of genuine apps. Denise Giusto Bili\u0107, Security Researcher at ESET, summarises some of the common behaviours of malicious Android code over the last few years.<\/em><\/p>\n<p><strong>Deceit based on social engineering<\/strong><\/p>\n<p><strong>Use fraudulent accounts in the Google Play Store to distribute malware<\/strong><\/p>\n<p>Malware in the official Google store\u00a0never stops appearing. For cybercriminals, sneaking their malicious applications into the marketplace of genuine apps is a huge victory as they can reach many more potential victims, thus having an almost rock-solid guarantee of more infections.<\/p>\n<p>What\u2019s more, the fake developer accounts used to spread insecure or malicious apps try to look as similar as possible to real accounts in order to dupe unsuspecting users who end up getting confused by them. In a recent example of this, researchers discovered a\u00a0fake app for updating WhatsApp\u00a0that used a\u00a0Unicode character trick\u00a0to give the impression of being distributed through the official account.<\/p>\n<p><strong>Take advantage of commemorative dates and scheduled app release dates<\/strong><\/p>\n<p>A common practice in the world of cybercrime is to make malware look like versions of apps \u2013 games, mostly \u2013 that have gained sudden popularity, which are either scheduled for release or are not available in official stores for certain countries. This happened with\u00a0Pok\u00e9mon GO,\u00a0Prisma\u00a0and\u00a0Dubsmash, adding hundreds of thousands of infections worldwide.<\/p>\n<p><strong>\u00a0<\/strong><strong>Tapjacking and overlay windows<\/strong><\/p>\n<p>Tapjacking\u00a0is a technique that involves capturing a user\u2019s screen taps by displaying two superimposed apps. Victims believe that they are tapping on the app that they are seeing, but they are actually tapping on the underlying app, which remains hidden from view.<\/p>\n<p>Another similar strategy, which is widely used in spyware for credential theft in Android, is\u00a0overlay windows. In this scam, the malware continually tracks the app that the user is using and, when it coincides with a certain objective app, it displays its own dialogue box that looks just like the legitimate app, requesting credentials from the user.<\/p>\n<p><strong>Camouflaged among system apps<\/strong><\/p>\n<p>By far, the easiest way for malicious code to hide on a device is to pass itself off as a system app and go as unnoticed as possible. Malpractices such as deleting the app icon once the installation is finished or using names, packages and icons of system apps and other popular apps to compromise a device are strategies that are emerging in code \u2013 like the\u00a0banking Trojan that passed itself off as Adobe Flash Player\u00a0to steal credentials.<\/p>\n<p><strong>Simulating system and security apps to request administrator permissions<\/strong><\/p>\n<p>Since Android is structured to limit app permissions, a lot of malicious code needs to request administrator permissions to implement its functionality correctly. And granting this permission makes it more difficult to uninstall the malware.<\/p>\n<p>Being\u00a0camouflaged as security tools\u00a0or system updates gives cybercriminals certain advantages. In particular, it allows them to shield themselves behind a trusted developer and, consequently, users do not hesitate to authorise the app to access administrative functions.<\/p>\n<p><strong>Security certificates that simulate true data<\/strong><\/p>\n<p>The security certificate used to sign\u00a0an APK\u00a0can also be used to determine if an app has been altered. And while most cybercriminals use generic text strings when issuing a certificate, many go to the trouble of feigning data that corresponds to the data used by the developer, going one step further in their efforts to confuse users who carry out these checks.<\/p>\n<p><strong>Techniques for complicating analysis<\/strong><\/p>\n<p><strong>Multiple functionalities in the same code<\/strong><\/p>\n<p><strong>\u00a0<\/strong>A trend that has been gaining ground in recent years in the mobile world is to combine what used to be different types of malware into a single executable.\u00a0LokiBot\u00a0is one example of this, which is a banking Trojan that tries to go unnoticed for as long as possible in order to steal information from a device. However, if the user tries to remove the administrator\u2019s permissions to uninstall it, it activates its ransomware feature by encrypting the device\u2019s files.<\/p>\n<p><strong>Hidden apps<\/strong><\/p>\n<p>The use of\u00a0droppers\u00a0and\u00a0downloaders, such as embedding malicious code inside another APK or downloading it from the Internet, is a strategy that is not only limited to malware for laptops and computers but is also universally used by malicious mobile code writers.<\/p>\n<p>As the then-known Google Bouncer (now rebranded as Google Play Protect) complicated cybercriminals\u2019 ability to upload malware to the official store, the attackers chose to include this type of behaviour to try to bypass controls \u2013 and it worked. Well, for a while at least.<\/p>\n<p>Since then, these two forms of malware coding have been added to the portfolio of most-used malicious techniques.<\/p>\n<p><strong>Multiple programming languages and volatile code<\/strong><\/p>\n<p>New multi-platform development\u00a0frameworks\u00a0and new programming languages are emerging all the time. What better way to mislead a malware analyst than to combine languages and development environments, such as designing apps with\u00a0Xamarin\u00a0or using Lua code to execute malicious commands. This strategy changes the final architecture of the executable and adds levels of complexity.<\/p>\n<p>Some attackers add to this combo by using dynamic script loading or portions of code that are downloaded from remote servers and deleted after use. So once the server has been removed by the cybercriminal, it is not possible to know exactly what actions the code performed on the device.<\/p>\n<p>Samples with these characteristics began to appear towards the end of 2014, when\u00a0researchers published this particularly complex malware analysis.<\/p>\n<p><strong>Synergistic malware<\/strong><\/p>\n<p>An alternative for complicating the analysis of a sample is to divide the malicious functionality into a set of apps that are capable of interacting with each other. By doing so, each app has a subset of permissions and malicious functionality and they then interact with each other to fulfil a further purpose. Moreover, for analysts to understand the true function of the malware they must have access to all the individual apps as if they were pieces of a puzzle.<\/p>\n<p>And while this is not a commonly-used strategy, there have already been samples that exhibit this type of behaviour.<\/p>\n<p><strong>Covert channels and new communication mechanisms<\/strong><\/p>\n<p>To communicate with a C&amp;C server or other malicious apps, malware needs to transfer information. This can be done via traditional open channels or\u00a0hidden channels\u00a0(personalised communication protocols, brightness intensity, wake locks, CPU utilization, free space in memory, sound or vibration levels and accelerometers, among others).<\/p>\n<p>Furthermore, in recent months we have seen how cybercriminals are using social networks to transfer C&amp;C messages, such as\u00a0\u2018Twitoor\u2019, the botnet that uses Twitter accounts to send commands.<\/p>\n<p><strong>\u00a0O<\/strong><strong>ther anti-analysis techniques<\/strong><\/p>\n<p>The use of\u00a0packaging,\u00a0anti-emulation,\u00a0anti-debugging,\u00a0encryption\u00a0and\u00a0obfuscation, among other\u00a0evasion techniques,\u00a0is very common in malware for Android. To get around these types of protections, it is possible to use\u00a0hooking of functions, perhaps through apps such as\u00a0Frida.<\/p>\n<p>It is also possible to use analysis environments that try to dodge these controls by default, such as\u00a0MobSF \u2013 which includes some anti-emulation techniques,\u00a0Inspeckage \u2013 where, for example, flat text strings can be seen before and after being encrypted, together with the keys used or AppMon.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>&nbsp; Malware in the official Google store never stops appearing \u2013 it is a \u2018huge victory\u2019 for cybercriminals to sneak their malicious applications into the marketplace of genuine apps. Denise Giusto Bili\u0107, Security Researcher at ESET, summarises some of the common behaviours of malicious Android code over the last few years. Deceit based on social [&hellip;]<\/p>\n","protected":false},"author":28,"featured_media":25727,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[6,13],"tags":[100,296,3106,5610,281,5611,104,541],"class_list":["post-25532","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-insights","category-top-stories","tag-android","tag-apps","tag-cybercriminals","tag-denise-giusto-bilic-security-researcher-at-eset","tag-google","tag-google-play-store","tag-malware","tag-mobile-technology-2"],"acf":[],"publishpress_future_workflow_manual_trigger":{"enabledWorkflows":[]},"_links":{"self":[{"href":"https:\/\/www.intelligentcio.com\/me\/wp-json\/wp\/v2\/posts\/25532","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.intelligentcio.com\/me\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.intelligentcio.com\/me\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.intelligentcio.com\/me\/wp-json\/wp\/v2\/users\/28"}],"replies":[{"embeddable":true,"href":"https:\/\/www.intelligentcio.com\/me\/wp-json\/wp\/v2\/comments?post=25532"}],"version-history":[{"count":3,"href":"https:\/\/www.intelligentcio.com\/me\/wp-json\/wp\/v2\/posts\/25532\/revisions"}],"predecessor-version":[{"id":25545,"href":"https:\/\/www.intelligentcio.com\/me\/wp-json\/wp\/v2\/posts\/25532\/revisions\/25545"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.intelligentcio.com\/me\/wp-json\/wp\/v2\/media\/25727"}],"wp:attachment":[{"href":"https:\/\/www.intelligentcio.com\/me\/wp-json\/wp\/v2\/media?parent=25532"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.intelligentcio.com\/me\/wp-json\/wp\/v2\/categories?post=25532"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.intelligentcio.com\/me\/wp-json\/wp\/v2\/tags?post=25532"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}