Showing posts with label Trojan. Show all posts
Showing posts with label Trojan. Show all posts

Android Botnet Infects Over 1 Million Phones in China

A piece of mobile malware believed to be hidden in around 7,000 Android applications has infected the devices of over 1 million users from China. Experts say that this may be the largest Android botnet the country has ever seen.

According to Chinese publication Xinhua, the Trojan that powers the botnet is Android.Troj.mdk, a threat first discovered back in 2011.

Once it’s installed on a device, the Trojan allows its master to take complete control of it. The malicious element can be used to harvest messages, phone numbers, contact details, geo-location data and even media files.

Bitdefender experts note that the Trojan also downloads additional applications that slow down the phone’s performance, generate aggressive adware, and drain the device’s battery.

With over 420 million mobile users, China has become an important target for malware developers.

Trojan disables Mac's built-in security defences

mac-trojan.jpg
Malware coders have created a Mac-specific Trojan that is designed to attack anti-malware defences built into Apple's Mac OS X operating system.

The Flashback.C trojan disables the automatic update component of XProtect, OS X's anti-malware application, net security firm F-Secure reports. By wiping out files, the malware prevents future updates, making it more likely that the devilish code will be able to stick around for longer.

The approach mimics a tactic long seen in the world of Windows malware, where attempts to disable security software have been commonplace for years as well as illustrating the growing sophistication of crooks targeting Macs with malware.

"Attempting to disable system defences is a very common tactic for malware — and built-in defences are naturally going to be the first target on any computing platform," F-Secure notes.

The Flashback.C Trojan poses as a Flash Player installer. In reality, the malware sets up a backdoor connection to a remote host. Although currently inactive, the remote host linked to the malware might be used to push any manner of crud onto infected machines.

Previous versions of the Flashback Trojan shunned virtual machines, a technique designed specifically to frustrate anti-virus analysis.