SoylentNews
SoylentNews is people
https://soylentnews.org/

Title    Android Users Hit With 'Unkillable Malware'
Date    Wednesday April 08 2020, @07:57PM
Author    Fnord666
Topic   
from the rooted-in-your-phone dept.
https://soylentnews.org/article.pl?sid=20/04/08/1625229

Arthur T Knackerbracket has found the following story:

An Android malware package likened to a Russian matryoshka nesting doll has security researchers raising the alarm, since it appears it's almost impossible to get rid of.

Known as xHelper, the malware has been spreading mainly in Russia, Europe, and Southwest Asia on Android 6 and 7 devices (which while old and out of date, make up around 15 per cent of the current user base) for the past year from unofficial app stores. Once on a gizmo, it opens a backdoor, allowing miscreants to spy on owners, steal their data, and cause mischief.

It has only recently been picked apart by Kaspersky Lab bods, and what makes the malware particularly nasty, the researchers say, is how it operates on multiple layers on the tablets and handsets it infects.

"The main feature of xHelper is entrenchment," explained Igor Golovin on Tuesday. "Once it gets into the phone, it somehow remains there even after the user deletes it and restores the factory settings."

[...] The best thing to do, though, is go a step further than a factory reset, and erase the flash memory completely, including the system partition, and put in a fresh clean copy. "If you have Recovery mode set up on your Android smartphone," said Golovin, "you can try to extract the libc.so file from the original firmware and replace the infected one with it, before removing all malware from the system partition. However, it’s simpler and more reliable to completely reflash the phone."

Even better advice is to avoid downloading any suspicious apps from the Google Play Store, just to be safe, and definitely don't use unauthorized third-party stores at all.


Original Submission

Links

  1. "following story" - https://www.theregister.co.uk/2020/04/08/xhelper_android_malware/
  2. "explained" - https://securelist.com/unkillable-xhelper-and-a-trojan-matryoshka/96487/
  3. "Original Submission" - https://soylentnews.org/submit.pl?op=viewsub&subid=40296

© Copyright 2024 - SoylentNews, All Rights Reserved

printed from SoylentNews, Android Users Hit With 'Unkillable Malware' on 2024-04-16 18:58:17