Feeds

'BadNews is malware' says outfit that found it

Google says code harmless but Lookout says code base is evolving

Choosing a cloud hosting partner with confidence

The BadNews malware debate continues to be batted back and forth, with Lookout, the company that first raised the alarm, maintaining that it is malware in the face of Google's assertion last week that it had seen no malicious activity associated with apps carrying the malware.

In conversation with The Register, Lookout's security product manager Jeremy Linden said the company not only remains confident that BadNews is malware, but that the security vendor is seeing “evolution of the code base”.

When BadNews was discovered, Lookout said it was present in 32 apps on Google Play which, combined, had been downloaded millions of times.

Last week, Google told a security conference “it had no evidence that BadNews was playing a part in the distribution of SMS-borne frauds”, adding that “we haven't seen a single instance of abusive SMS applications being downloaded as a result of BadNews”.

Linden has now told The Register that “Our analysis confirms that BadNews does prompt the user to install a malware application,” but that it was written “to avoid detection”. It remains quiet most of the time, he said, only becoming active for a few minutes at a time.

“There's a high possibility that Google hasn't seen it sending malware,” Linden told The Register. “We have systems that act like they're infected clients, so they can sit on the malware networks and log malicious traffic.

“We are still seeing traffic from BadNews and we're seeing an evolution of the code base.”

He said that BadNews' operators are “adding features” to increase the malicious activity of the malware, and said Lookout believes “the same developers are behind other explicitly malicious code.”

The Register invited Google to provide comment for this story, but has received no response. ®

Choosing a cloud hosting partner with confidence

More from The Register

next story
'Regin': The 'New Stuxnet' spook-grade SOFTWARE WEAPON described
'A degree of technical competence rarely seen'
You really need to do some tech support for Aunty Agnes
Free anti-virus software, expires, stops updating and p0wns the world
You stupid BRICK! PCs running Avast AV can't handle Windows fixes
Fix issued, fingers pointed, forums in flames
Privacy bods offer GOV SPY VICTIMS a FREE SPYWARE SNIFFER
Looks for gov malware that evades most antivirus
Patch NOW! Microsoft slings emergency bug fix at Windows admins
Vulnerability promotes lusers to domain overlords ... oops
HACKERS can DELETE SURVEILLANCE DVRS remotely – report
Hikvision devices wide open to hacking, claim securobods
prev story

Whitepapers

Choosing cloud Backup services
Demystify how you can address your data protection needs in your small- to medium-sized business and select the best online backup service to meet your needs.
Getting started with customer-focused identity management
Learn why identity is a fundamental requirement to digital growth, and how without it there is no way to identify and engage customers in a meaningful way.
5 critical considerations for enterprise cloud backup
Key considerations when evaluating cloud backup solutions to ensure adequate protection security and availability of enterprise data.
High Performance for All
While HPC is not new, it has traditionally been seen as a specialist area – is it now geared up to meet more mainstream requirements?
How to simplify SSL certificate management
Simple steps to take control of SSL certificates across the enterprise, and recommendations centralizing certificate management throughout their lifecycle.