1、安卓银行木马Tordow具备root设备能力
标题:Android Phones Under Attack As New Malware Can Root Devices, Steal Passwords
Comodo warns of new version of Tordow Android malware
作者信息:Dec 16, 2016 08:55 GMT By Bogdan Popa
//BEGIN
Devices running Android are being targeted by a new version of the Tordow malware, which was originally discovered earlier this year and attempts to obtain root privileges to perform a series of actions, such as stealing passwords.
安全公司发现一个Android木马的Tordow最新变种2.0:当前主要是感染俄罗斯的用户,当然只要愿意,它可以感染任何其他的地区的“用户”。
由于其具备Root功能,因此能干的事情其实很多:
拨打电话;读取短信;下载并安装程序;盗取登录验证码;访问用户的通讯录;加密文件;访问指定网页;访问用户的银行登录数据;卸载安全软件;重启手机;给文件改名甚至可以装扮成勒索软件的样子。
尽管如此,当下该木马的主要功能还是作为网银木马的面目示人。
感染该木马其实必须有用户的直接参与并允许才能进行:通常是通过在一些不正规的第三方所谓APP商店中被感染。经过监测发现:热门游戏Pokemon Go、社交工具Telegram,以及日常应用Subway Surfers等都被植入了该木马。用户应该特别小心。
这些大多是通过APK文件的形式来传播和感染的,因此用户在进行社交活动或者访问不知名网站时要特别注意:谨记从正规的APP应用商店下载各种流行应用。
//END
How it works
Once installed with a malicious app, the Trojan attempts to gain root privileges and then connect to a command-and-control center to wait for more commands.
Afterward, attackers can do anything they want, but for the moment, it appears that bank accounts are primarily targeted, as cybercriminals want financial information from Russian users.
Removing Tordow from an infected device is particularly difficult since it gets root access, so flashing a new firmware might be the best way to do it, as
deleting the source app that led to the infection does virtually nothing.
由于该APP具备Root功能,因此一旦感染清除是非常困难的,除非重新刷机。即使删除感染的源头APP也无济于事。
点评:Android下的安全推荐AVL Pro! |