Trojan uses LiveCD for Android running on x86 platforms as bait
June 2010
IT in Manufacturing
With the growing interest in testing the new Android OS on x86 platforms, cybercriminals are looking to exploit vulnerable users wanting to install the operating system on their PCs. A piece of malware is hosted by a fake webpage, imitating the original Android LiveCD one, and offering the 'hunted' software.
In essence, Google Android is a Linux kernel-based operating system for mobile phones. The statistics published on different Android-related sites and mobile advertising networks reflect its success worldwide:
* About 60 000 Android phones are sold daily and about 22 000 000 a year.
* Android Market delivers over 30 000 Android Apps.
* About 60% of Android Apps are free.
* 167 Apps have been downloaded between between 667 000 and 2,9 million times.
* The average paid Android app is priced at $3,27.
Android-powered Netbooks have recently appeared on the market, meaning that Android OS can now be installed on Netbooks and, of course, on normal PCs. A quick search on the Internet for 'Android on PC' and, here it is: a long list of sites offering the possibility to test the new OS on x86 Windows platforms.
Figure 1. Results for 'Andoid on PC' Internet search
An apparently unsuspicious link in the returned list of results, one click, and the user is redirected to a look-alike of the LiveAndroid page, which, instead of the promised OS for PCs, delivers a Trojan.
Figure 2. Trojan instead of Android OS
Identified by BitDefender as Trojan.Generic.KD.13718, this piece of malware affects only Windows platforms and contains malicious or potentially unwanted software which it drops and installs on the system. Frequently, it installs a backdoor which allows remote, clandestine access to the infected system. This backdoor may then be used by cybercriminals to upload and install additional malicious or potentially unwanted software on the captured system.
A closer look at the fallacious site and at the downloaded file reveals several differences, the most important of which being that the downloaded file should have an .iso image, not an .exe extension. The sites may look the same, but there are a few minor details that will set the bogus apart from the genuine one (as indicated in the screenshots below):
Figure 3. Original Live Android site vs. Fake Live Android site
In order to stay safe, BitDefender recommends you to install and update a complete antimalware software solution on your system.
Other details about this malware alert:
For more information contact: Alina Anton, senior PR and marketing coordinator, EMEA & APAC Business Unit, BitDefender, +40 212 063 470, [email protected], www.bitdefender.com
Further reading:
Why choose between Capex and Opex if you can Totex?
Schneider Electric South Africa
IT in Manufacturing
In a sector marked by cyclical demand, high capital intensity, and increasing regulatory and sustainability pressures, mining, minerals and metals (MMM) companies are re-evaluating how they approach procurement and investment.
Read more...
AI and the smart factory
Schneider Electric South Africa
IT in Manufacturing
Imagine walking into a factory where machines can think ahead, predict problems before they happen and automatically make adjustments to realise peak performance. This isn’t science fiction, it’s happening right now as AI continues to transform how we run industrial operations.
Read more...
Why your supply chain should be a competitive advantage
Schneider Electric South Africa
IT in Manufacturing
The last five years have placed unprecedented strain on global supply chains. Leading companies are turning the challenge into an opportunity to transform their supply chains into a competitive advantage.
Read more...
Why AI will never truly understand machines
Wearcheck
IT in Manufacturing
Cutting-edge technology and solutions powered by AI are embraced by specialist condition monitoring company, WearCheck, where the extreme accuracy of data used to assess and diagnose machine health is paramount.
Read more...
Buildings and microgrids for a greener future
Schneider Electric South Africa
IT in Manufacturing
Buildings are no longer passive consumers of power. Structures of almost every size are evolving into dynamic energy ecosystems capable of generating, storing and distributing their own electricity. Forming part of this exciting transformation are microgrids.
Read more...
Traditional data centres are not fit for purpose
IT in Manufacturing
Traditional data centre designs are falling short, with nearly half of IT leaders admitting their current infrastructure does not support energy or carbon-reduction goals. New research commissioned by Lenovo reveals that data centre design must evolve to future-proof businesses.
Read more...
AI agents for digital environment management in SA
IT in Manufacturing
The conversation about artificial intelligence in South Africa has shifted rapidly over the past year. Among the technologies changing the pace of business are AI agents - autonomous, task-driven systems designed to operate with limited human input.
Read more...
AI-powered maintenance in future-ready data centres
Schneider Electric South Africa
IT in Manufacturing
The data centre marketplace often still relies on outdated maintenance methods to manage mission-critical equipment. Condition-Based Maintenance (CBM) is powered by AI and is fast becoming a necessity in ensuring both competitiveness and resilience.
Read more...
Powering up data centre mega development
IT in Manufacturing
Parker Hannifin has secured a major contract to supply key equipment for nearly 30 aeroderivative gas turbines powering a new hyperscale data centre in Texas.
Read more...
Building resilient supply chains through smarter e-procurement
RS South Africa
IT in Manufacturing
In a time of constant disruption, from supply chain uncertainty to rising operational costs, businesses that embrace digital procurement are better positioned to stay competitive and resilient.
Read more...