Feeds

Tibetan and Uyghur activists targeted with Android malware

Hmm ... who'd want to do that?

The Essential Guide to IT Transformation

Researchers at Kaspersky Lab are reporting that Tibetan activists are being hit by a highly targeted form of Android malware that seeks to record their contacts, call logs, SMS messages, geolocation, and phone data.

The attack started with the March 24 hacking of an email account belonging to an activist seeking national independence for Tibet.

All of the activist's contacts then received a message urging them to check out details from the forthcoming World Uyghur Congress meeting being held in Geneva to discuss human rights. An Android Package (APK) file containing a software nasty was enclosed with the email.

The malware, dubbed Backdoor.AndroidOS.Chuli.a by the researchers, launches what appears to be a standard Android app that apparently contains a message from "Dolkun lsa, chairman of the executive committee of the Word [sic] Uyghur Congress." However, the app also installs a bugging program that's controlled by SMS.

When the correct control message comes in via SMS, the malware sends the information, encoded in Base 64, to a command and control (C&C) server running Windows Server 2003 and configured in Chinese. The commands to control the code contain Chinese characters, and the C&C servers are located in Los Angeles, but the commands travel via a domain registered to a Chinese firm.

"The current attack took advantage of the compromise of a high-profile Tibetan activist. It is perhaps the first in a new wave of targeted attacks aimed at Android users," said the Kaspersky Lab research team.

"So far, the attackers relied entirely on social engineering to infect the targets. History has shown us that, in time, these attacks will use zero-day vulnerabilities, exploits or a combination of techniques."

While there's no direct evidence that the attack code is being run by the Chinese government, it does seem from the evidence that the malware comes from the Middle Kingdom. Additionally, one has to consider who would want to track down and monitor Tibetan and Uyghur activists.

Based on Occam's Razor, the evidence suggests the Chinese government is up to its old tricks. ®

Build a business case: developing custom apps

More from The Register

next story
14 antivirus apps found to have security problems
Vendors just don't care, says researcher, after finding basic boo-boos in security software
'Things' on the Internet-of-things have 25 vulnerabilities apiece
Leaking sprinklers, overheated thermostats and picked locks all online
iWallet: No BONKING PLEASE, we're Apple
BLE-ding iPhones, not NFC bonkers, will drive trend - marketeers
Only '3% of web servers in top corps' fully fixed after Heartbleed snafu
Just slapping a patched OpenSSL on a machine ain't going to cut it, we're told
How long is too long to wait for a security fix?
Synology finally patches OpenSSL bugs in Trevor's NAS
Secure microkernel that uses maths to be 'bug free' goes open source
Hacker-repelling, drone-protecting code will soon be yours to tweak as you see fit
Israel's Iron Dome missile tech stolen by Chinese hackers
Corporate raiders Comment Crew fingered for attacks
Roll out the welcome mat to hackers and crackers
Security chap pens guide to bug bounty programs that won't fail like Yahoo!'s
HIDDEN packet sniffer spy tech in MILLIONS of iPhones, iPads – expert
Don't panic though – Apple's backdoor is not wide open to all, guru tells us
prev story

Whitepapers

Implementing global e-invoicing with guaranteed legal certainty
Explaining the role local tax compliance plays in successful supply chain management and e-business and how leading global brands are addressing this.
Consolidation: The Foundation for IT Business Transformation
In this whitepaper learn how effective consolidation of IT and business resources can enable multiple, meaningful business benefits.
Backing up Big Data
Solving backup challenges and “protect everything from everywhere,” as we move into the era of big data management and the adoption of BYOD.
Boost IT visibility and business value
How building a great service catalog relieves pressure points and demonstrates the value of IT service management.
Why and how to choose the right cloud vendor
The benefits of cloud-based storage in your processes. Eliminate onsite, disk-based backup and archiving in favor of cloud-based data protection.