Feeds

Tainted apps worm into official Android store

DroidDream creates security nightmare

Providing a secure and efficient Helpdesk

Dozens of tainted applications have been discovered on the official Android Market.

More than 50 applications have been found to be infected with a new type of Android malware called DroidDream, an information stealer. Fraudsters repackaged legitimate apps (mostly games) so that they included malicious code before uploading them to the marketplace. The tactic has been seen in mobile marketplaces in China and elsewhere but this is the first time the approach has been successfully applied in the US, mobile security firm Lookout reports.

Google responded to the reports of problems by purging the apps from its mobile marketplace. Credit for initially noticing a potential problem goes to Lompolo, a user at popular news aggregator site to Reddit.

The scare over modified apps on the official Android Market follows a security flap on third-party app stores late last week. Scammers modified an app called Steamy Window to incorporate backdoor code before uploading it to third-party stores. The malign application is designed to surreptitiously send text messages to premium rate numbers, earning scammers a commission in the process while leaving victims well out of pocket and probably unaware of the scam prior to receiving a bumper bill. The malware, which is capable of downloading other malign applications, blocks alerts telling phone users that they've exceeded their quota of texts.

The malware – dubbed Android Pjapps by Symantec – also has the capability to navigate to websites and add bookmarks to the user's browser, characteristics that would come in handy for running click fraud internet ad scam campaigns. ®

Choosing a cloud hosting partner with confidence

More from The Register

next story
Same old iPad? NO. The new 'soft SIMs' are BIG NEWS
AppleSIM 'ware to allow quick switch of carriers
Arab States make play for greater government control of the internet
Nerds told to get lost in last-minute power grab bid at UN meeting
Brits: Google, can you scrape 60k pages from web, pleeease
Hey, c'mon Choc Factory, it's our 'right to be forgotten'
Of COURSE Stephen Elop's to blame for Nokia woes, says author
'Google did have some unique propositions for Nokia'
It's even GRIMMER up North after MEGA SKY BROADBAND OUTAGE
By 'eck! Eccles cake production thrown into jeopardy
Mobile coverage on trains really is pants
You thought it was just *insert your provider here*, but now we have numbers
Don't mess with Texas ('cos it's getting Google Fiber and you're not)
A bit late, but company says 1Gbps Austin network almost ready to compete with AT&T
prev story

Whitepapers

Forging a new future with identity relationship management
Learn about ForgeRock's next generation IRM platform and how it is designed to empower CEOS's and enterprises to engage with consumers.
Why cloud backup?
Combining the latest advancements in disk-based backup with secure, integrated, cloud technologies offer organizations fast and assured recovery of their critical enterprise data.
Win a year’s supply of chocolate
There is no techie angle to this competition so we're not going to pretend there is, but everyone loves chocolate so who cares.
High Performance for All
While HPC is not new, it has traditionally been seen as a specialist area – is it now geared up to meet more mainstream requirements?
Intelligent flash storage arrays
Tegile Intelligent Storage Arrays with IntelliFlash helps IT boost storage utilization and effciency while delivering unmatched storage savings and performance.