Article count:16428 Read by:87919360

Hottest Technical Articles
Exclusive: A senior executive of NetEase Games was taken away for investigation due to corruption
OPPO is going global, and moving forward
It is reported that Xiaohongshu is testing to directly direct traffic to personal WeChat; Luckin Coffee is reported to enter the US and hit Starbucks with $2, but the official declined to comment; It is reported that JD Pay will be connected to Taobao and Tmall丨E-commerce Morning News
Yu Kai of Horizon Robotics stands at the historical crossroads of China's intelligent driving
Lei Jun: Don't be superstitious about BBA, domestic brands are rising in an all-round way; Big V angrily criticized Porsche 4S store recall "sexy operation": brainless and illegal; Renault returns to China and is building a research and development team
A single sentence from an overseas blogger caused an overseas product to become scrapped instantly. This is a painful lesson. Amazon, Walmart, etc. began to implement a no-return and refund policy. A "civil war" broke out between Temu's semi-hosted and fully-hosted services.
Tmall 3C home appliances double 11 explosion: brands and platforms rush to
Shareholders reveal the inside story of Huayun Data fraud: thousands of official seals were forged, and more than 3 billion yuan was defrauded; Musk was exposed to want 14 mothers and children to live in a secret family estate; Yang Yuanqing said that Lenovo had difficulty recruiting employees when it went overseas in the early days
The app is coming! Robin Li will give a keynote speech on November 12, and the poster reveals a huge amount of information
It is said that Zhong Shanshan asked the packaged water department to sign a "military order" and the entire department would be dismissed if the performance did not meet the standard; Ren Zhengfei said that it is still impossible to say that Huawei has survived; Bilibili reported that employees manipulated the lottery丨Leifeng Morning News
Account Entry

40 cheap Android phones contain pre-installed banking malware, experts say a Shanghai software developer is the culprit

Latest update time:2018-03-04
    Reads:

Text | Dazhuang Brigade Editor: Li Qin

Report from Leiphone.com (leiphone-sz)

Leifeng.com news, are you still buying cheap Android smartphones for cheap? You should be more careful before buying. According to foreign media reports on March 3, US time, Dr.Web researchers found the terrible Triada banking malware in more than 40 cheap Android phones, and they were pre-installed.

Security researchers from antivirus company Dr.Web have isolated the Triada.231 banking malware from 42 cheap Android smartphones.

"In mid-2017, Dr.Web analysts discovered the new Triada.231 malware in the firmware of some cheap Android phones. Since then, the list of cheap Android phones infected with this malware has been growing," Dr-Web wrote in a blog post. "Now, more than 40 cheap Android phones have been infected. We have been monitoring the movement of this malware for a long time and now we can finally publish the final results of our investigation."

The Triada malware was first discovered by researchers at Kaspersky Lab in 2016. At the time, the researchers considered it to be the most advanced threat facing mobile devices.

Leifeng.com learned that when hackers designed Triada, they wanted to use it for financial fraud , the most typical of which was to use it for financial SMS transactions. The most interesting feature of this malware is that it uses a modular architecture, so in theory Triada can have a variety of destructive capabilities.

When inserting the code onto the device, the hackers used the Zygote process, which meant that the malware infiltrated every piece of software. There was only one way to eliminate the threat: wipe all the data on the smartphone and reinstall the entire operating system.

Researchers at Dr.Web pointed out that most of these Android smartphones pre-installed with malware are from small brands , with the hardest hit being brands that few people have ever heard of, such as Advan, Cherry Mobile, Doogee and Leagoo.

Dr.Web also revealed that the culprit of the malware infection was a software developer in Shanghai, which is a partner of Leagoo. "The Shanghai company provided Leagoo with an app that contained instructions to add third-party code to the system database before compilation. Unfortunately, the manufacturer did not refuse this controversial request. In the end, Triada.231 entered the smartphone openly," Dr.Web wrote in a blog post.

The infected app was also developed by a Chinese company, and security experts pointed out that the malware code is exactly the same as the software certificate that infected it in 2016.

"After analyzing this app, we found that it used the same certificate as the MulDrop.924 malware, and it is likely that the same people are behind it," Dr.Web wrote in a blog post.

The more than 40 infected Android phones mentioned in the article may be just a drop in the ocean, and the real blacklist of cheap phones may be larger than imagined.

Leifeng.com Via. Security Affairs

- END -



Three modules, five applications, quick introduction to NLP; overseas doctoral lecturers, rich project experience; algorithm + practice, with typical industry applications; learn anytime, professional community, lecturers answer questions online. Click for details Read the original text Link or long press to identify the QR code above~


Latest articles about

Database "Suicide Squad" 
Exclusive: Yin Shiming takes over as President of Google Cloud China 
After more than 150 days in space, the US astronaut has become thin and has a cone-shaped face. NASA insists that she is safe and healthy; it is reported that the general manager of marketing of NetEase Games has resigned but has not lost contact; Yuanhang Automobile has reduced salaries and laid off employees, and delayed salary payments 
Exclusive: Google Cloud China's top executive Li Kongyuan may leave, former Microsoft executive Shen Bin is expected to take over 
Tiktok's daily transaction volume is growing very slowly, far behind Temu; Amazon employees exposed that they work overtime without compensation; Trump's tariff proposal may cause a surge in the prices of imported goods in the United States 
OpenAI's 7-year security veteran and Chinese executive officially announced his resignation and may return to China; Yan Shuicheng resigned as the president of Kunlun Wanwei Research Institute; ByteDance's self-developed video generation model is open for use丨AI Intelligence Bureau 
Seven Swordsmen 
A 39-year-old man died suddenly while working after working 41 hours of overtime in 8 days. The company involved: It is a labor dispatch company; NetEase Games executives were taken away for investigation due to corruption; ByteDance does not encourage employees to call each other "brother" or "sister" 
The competition pressure on Douyin products is getting bigger and bigger, and the original hot-selling routines are no longer effective; scalpers are frantically making money across borders, and Pop Mart has become the code for wealth; Chinese has become the highest-paid foreign language in Mexico丨Overseas Morning News 
ByteDance has launched internal testing of Doubao, officially entering the field of AI video generation; Trump's return may be beneficial to the development of AI; Taobao upgrades its AI product "Business Manager" to help Double Eleven丨AI Intelligence Bureau 

 
EEWorld WeChat Subscription

 
EEWorld WeChat Service Number

 
AutoDevelopers

About Us Customer Service Contact Information Datasheet Sitemap LatestNews

Room 1530, Zhongguancun MOOC Times Building,Block B, 18 Zhongguancun Street, Haidian District,Beijing, China Tel:(010)82350740 Postcode:100190

Copyright © 2005-2024 EEWORLD.com.cn, Inc. All rights reserved 京ICP证060456号 京ICP备10001474号-1 电信业务审批[2006]字第258号函 京公网安备 11010802033920号