Over 80 Percent of Android Users Still at Risk of Being Infected by Dated Malware Ghost Push: Report

October 19, 2016

Oct 19: Apple has consistently taken digs at Google by comparing the adoption rate of the latest versions of both iOS and Android at its launch events. It seems the slow adoption rate is one of the key reasons why a large chunk of Android users are still not safe from dated malware.

AndroidGhost Push, the malware that had infected over 900,000 Android devices till last year, continues to wreak havoc on smartphones and tablets running Google's mobile operating system, according a new report by Chinese antivirus firm Cheetah Mobile. The study says that the malware is infecting 10,000 new devices a day even now, and over 50 percent of the affected devices are from India.

It has been more than a year since Cheetah Mobile first discovered the malware Ghost Push. In its latest report, the firm has claimed that smartphones running Lollipop and older Android versions are still vulnerable to the malware, which has evolved since over the past year.

The report says that the malware is not able to infect Android versions starting from Android 6.0 but can potentially infect devices on all versions up to Marshmallow. Ghost Push malware first obtains root access to the affected Android device and then installs more malicious apps.

As per Google's Android distribution data from September, only 18.7 percent of Android users are running Android 6.0 Marshmallow or above, which effectively means that 81.3 percent of the total Android users are at a potential risk of getting affected by this malware.

The malware not only displays ads and promotes apps and web pages but can also lead users to pornographic websites. It can also show advertisements in the Notification Bar. Ghost Push trojans are promoting as many as 30,000 to 40,000 apps on infected devices, including legitimate apps as well as malware.

As last year's report had noted, the malware had managed to find its way to inside of many Google Play apps. Now, the firm is saying that the installation of apps from unknown sources is one of the major reasons for the devices to get affected by this malware. Popular apps like MX Player Pro, ES File Manager Pro, Run Keeper, Firefox and Music Player Pro, if downloaded from unknown sources, can be potentially infected with Ghost Push.

It is highly advisable for all Android users to constantly update their devices with the latest software upgrades - if available - in order to ensure that they are protected against these kinds of threats.

Comments

Add new comment

  • Coastaldigest.com reserves the right to delete or block any comments.
  • Coastaldigset.com is not responsible for its readers’ comments.
  • Comments that are abusive, incendiary or irrelevant are strictly prohibited.
  • Please use a genuine email ID and provide your name to avoid reject.
Agencies
May 22,2020

Kochi, May 22: During the nationwide COVID-19 lockdown, Kerala recorded the highest number of cyber attacks followed by Punjab and Tamil Nadu, a study by anti-virus software firm K7 Computing said on Thursday.

In a statement issued in Chennai, the company said its K7 Computing's Cyber Threat Report, a comprehensive analysis of cyber attacks during the lockdown has found that Kerala recorded the highest number of cyber attacks during this period. The report analyses various cyber attacks within India during the pandemic and reveals that threat actors targeted the state with COVID-themed attacks aimed at exploiting user trust.

In Kerala, regions like Kottayam, Kannur, Kollam, and Kochi saw the highest hits with 462, 374, 236, and 147 attacks respectively, while the state as a whole saw around 2,000 attacks during the period - the highest thus far in the country.

This was followed by Punjab with 207 attacks and Tamil Nadu with 184 attacks, the company said.

The sudden surge in the frequency of attacks witnessed from February 2020 to mid-April 2020 indicates that scamsters across the world were exploiting the widespread panic around coronavirus at both the individual and corporate level.

These attacks aimed to compromise computers and mobile devices to gain access to users' confidential data, banking details, and cryptocurrency accounts.

The key threats seen during this period ranged from phishing attacks to rogue apps disguised as COVID-19 information apps that targeted users' sensitive data. Phishing attacks were noticed more in Tier-II and Tier-III cities while the metros fared better. Smaller cities saw over 250 attacks being blocked per 10,000 users.

Users from Ghaziabad and Lucknow seem to have faced almost 6 and 4 times the number of attacks as Bengaluru users.

According to the statement, a majority of the recorded attacks were phishing attacks with sophisticated campaigns that could easily snare even the most educated users. These attacks were aimed at heightening users' fears and creating a sense of urgency to take action.

K7 Labs noticed phishing attacks where scamsters posed as representatives of the United States Department of Treasury, the World Health Organization (WHO), and the Centres for Disease Control and Prevention (CDC), the company said.

Users were encouraged to visit links that would automatically download malware on the host computer such as the Agent Tesla keylogger or Lokibot information-stealing malware, infamous banking Trojans such as Trickbot or Zeus Sphinx, and even disastrous ransomware.

Other attacks included infected COVID-19 Android apps like CoronaSafetyMask that scam users with promises of masks for an upfront payment; the spyware app Project Spy; and seemingly genuine apps that are infected with dangerous malware like banking Trojans such as Ginp, Anubis and Cerberus.

"Covid-19 has created an ideal situation for various threat actors to target individuals and enterprises alike. The panic caused by the stringent lockdown measures and rapid spread of this virus has left many people looking for more information on the situation," J. Kesavardhanan, Founder and CEO of K7 Computing was quoted as saying in the statement.

"Threat actors exploit this fear to their advantage and scam users into downloading malicious software and divulging sensitive information like banking codes. The need to be cyber cautious has never been greater. This is more so in the case of corporates who have adopted a work from home policy hurriedly without adequate cyber hygiene. We have seen an increase in attacks on enterprises and SME employees as well," he added.

Such attacks are expected to continue till normalcy returns. Social engineering attacks targeted at winning users' trust will gain momentum.

Healthcare institutions, well-known government offices, and international organisations will continue to be a prime target throughout the pandemic, the statement said.

Comments

Add new comment

  • Coastaldigest.com reserves the right to delete or block any comments.
  • Coastaldigset.com is not responsible for its readers’ comments.
  • Comments that are abusive, incendiary or irrelevant are strictly prohibited.
  • Please use a genuine email ID and provide your name to avoid reject.
Agencies
May 15,2020

Kolkata, May 15: Veteran Bengali author Debesh Roy, who was conferred the Sahitya Akademi award for his novel 'Teesta Parer Brittanto', died at a private hospital in Kolkata on Thursday, his family members said.

Roy was 84 and he is survived by his son. His wife had died earlier.

He was admitted to the hospital near his residence at Baguihati, in the eastern fringes of the city, on Wednesday after having symptoms like sodium potasium imbalance, sugar problem and breathing problem, his family members said.

He suffered a massive cardiac arrest and died at 10.50 PM.

A regular contributor to a number of Bengali dailies, he was a staunch critic of the attacks on liberals by in the country in recent times and attended protest meetings despite his failing health.

He was born in Pabna in present-day Bangladesh on December 17, 1936. He had five decades of career as a writer.

Besides Teesta Parer Britanta', he will be remembered for books like Borisaler Jogen Mondal , Manush Khun Kore Keno and Samay Asamayer Brittanto . His first book was Jajati.

His last rites will be performed tomorrow.

Comments

Add new comment

  • Coastaldigest.com reserves the right to delete or block any comments.
  • Coastaldigset.com is not responsible for its readers’ comments.
  • Comments that are abusive, incendiary or irrelevant are strictly prohibited.
  • Please use a genuine email ID and provide your name to avoid reject.
Agencies
March 8,2020

Consumer watchdog Which? has claimed that more than one billion Android phones and tablets are vulnerable to hackers as they no longer supported by security updates.

According to the research report, the most at-risk phones are any that run Android 4 or older and those smartphones running Android 7.0 which can not be updated are also at risk.

Based on data from Google analysed by Which?, two in five android device users around the world are no longer receiving the important updates. Currently, those devices are unlikely to have issues, but the lack of security leaves them open to attack.

"It is very concerning that expensive Android devices have such a short shelf life before they lose security support, leaving millions of users at risk of serious consequences if they fall victim to hackers," Kate Bevan editor Which? said in a statement.

"Google and phone manufacturers need to be upfront about security updates with clear information about how long they will last and what customers should do when they run out. The government must also push ahead with planned legislation to ensure manufacturers are far more transparent about security updates for smart devices and their impact on consumers," Kate added.

Android phone released around 2012 or earlier, including popular models like the Samsung Galaxy S3 and Sony Xperia S, are particularly at risk to hackers.

Which? has made suggestions to Android users on what to consider if they have an older phone that may be at risk.

Any Android device which is more than two years old, check whether it can be updated to a newer version of the operating system. If it is on an earlier version than Android 7.0 Nougat, try to update via Settings> System>Advanced System update.

In case a user is not able tto update the phone, the device could be at risk of being hacked if it is running a version of Android 4 or lower.

A user also need to be careful about downloading apps outside the Google Play store and should also install a mobile anti-virus via an app.

Comments

Add new comment

  • Coastaldigest.com reserves the right to delete or block any comments.
  • Coastaldigset.com is not responsible for its readers’ comments.
  • Comments that are abusive, incendiary or irrelevant are strictly prohibited.
  • Please use a genuine email ID and provide your name to avoid reject.