How Real Is The Malware Threat To Android?

Analysis
May 4, 20123 mins

We have heard of it, but do we really fear it?

Many of us have heard that our smartphones and tablets already are or soon will be the targets of attack by the malware industry (yes it is an industry). However, most of you probably don’t have any security software running on your devices. Why is that? Well, one of the big reasons is that for all of the talk we have not really seen malware that really does anything really bad to our phones yet. In fact, there may have even a bit of the “boy who cried wolf” going on where security companies pulled the firealarm for alleged malware outbreaks when the alleged malware was really just some adware

Hey, that would not be the first time that the security industry has used FUD to scare people into buying security software. But now we are seeing a bonafide malware attack on Android. The so-called Noncompatible trojan was detailed in a Netword Article by Ian Paul yesterday. I had a chance to speak with Liam O Murchu, manager of operations at Symantec Security Response, yesterday as well.

Many are detailing this as a “drive-by” attack where visitors are infected by just visiting a web site. Actually, according to Murchu, it is not a classic drive-by in that regard. When visitors go to a website, they receive a notification that an “update” is required for their phone. A user has to actually agree to install the update, which is how the malware is installed. According to Liam, the domains that have been discovered delivering this malware are:

  • [http://]androidbia.info
  • [http://]androidjea.info
  • [http://]gaoanalitics.info
  • [http://]androidonlinefix.info

This type of attack would not be successful on an iPhone for the above reason. Since the “jailbreakme.com” vulnerability Apple has made it almost impossible for any application to be installed on iOS unless it comes through the app store. Of course, it can’t get on the app store until it is checked by Apple. So this is a case of Android’s more open nature giving you more freedom to install apps from 3rd parties, as well as presenting a security risk.

In terms of what happens if you install the Trojan it appears that it could make your phone or device into a bot. It seems to allow the malware authors to use your device as a proxy. This means they could send spam through your device or perhaps launch some sort of coordinated DDoS attack. Symantec was not sure exactly when, how and where the trojan would be activated.

But lets be clear: this is a real trojan that was designed to infect Android machines. It is not just some app that is a bit aggressive on its adware. The time to install security software on your phone or tablet is now. Don’t wait until after subsequent attacks make you learn the lesson the hard way. There are many choices of both free and premium security suites available for Android, as well as iOS devices. An ounce of prevention is worth a pound of cure when it comes to malware.