Feeds

Sync'n'steal: Hackers brew Android-targeting Windows malware

Connect device to infected PC, kiss your bank balance bye-bye

Top three mobile application threats

Internet Igors have stitched together the first strain of Windows malware that can hop over and infect Android smartphones and tablets.

The Droidpak mobile banking trojan exploits syncing between smartphones and Windows PCs to jump from a compromised PC onto an Android device.

The Windows Trojan downloads a malicious .APK file (an Android application) onto an infected computer. The malware also downloads a command line Android Debug Bridge (ADB) tool, a utility that allows the malicious code to execute commands on Android devices connected to an infected computer.

ADB is a legitimate utility that's part of the official Android software development kit.

Ultimately the malware is used to intercept victims' SMS messages before relaying them to an attacker's server, an approach that defeats secondary channel confirmation of fraudulent banking transactions.

The Android malware works in conjunction with malware on an infected Windows device in order to carry out fraudulent transactions.

The combo is targeted against online banking users in South Korea. A write up of the malware can be found in a blog post by Symantec here.

The Droidpak trojan takes the opposite route to anther strain of malware, discovered by security researchers at Kapsersky Lab last year, which infects an Android smartphone or tablet before attempting to infect a Windows PC. ®

Combat fraud and increase customer satisfaction

Whitepapers

Securing web applications made simple and scalable
In this whitepaper learn how automated security testing can provide a simple and scalable way to protect your web applications.
3 Big data security analytics techniques
Applying these Big Data security analytics techniques can help you make your business safer by detecting attacks early, before significant damage is done.
The benefits of software based PBX
Why you should break free from your proprietary PBX and how to leverage your existing server hardware.
Mainstay ROI - Does application security pay?
In this whitepaper learn how you and your enterprise might benefit from better software security.
Combat fraud and increase customer satisfaction
Based on their experience using HP ArcSight Enterprise Security Manager for IT security operations, Finansbank moved to HP ArcSight ESM for fraud management.