Google Pulls 21 Malware Apps Posing as Bogus Versions of Real Apps


Sounds like a bogus app posing as Steamy Window is the least of our worried. That particular malware may do some damage if you install it, but at least you would never find it in the Android Market. That isn’t the case with a long list of 21 applications Google pulled last night (rather quickly, might I add) after being alerted to the malware that roots your device against your will using the rageinthecage exploit. This rooting is followed by the standard data snatching and open door for the download of even more malicious code.

Not only were the apps available directly from the Android Market, but they were designed to be easily confused with already popular games. Pirated APKs were infused with the malware then unleashed in the form of Chess, Scientific Calculator, and others. The unifying factor is that all were placed on the market under developer Myournet. Here is the full list:

  • Falling Down
  • Super Guitar Solo
  • Super History Eraser
  • Photo Editor
  • Super Ringtone Maker
  • Super Sex Positions
  • Hot Sexy Videos
  • Chess
  • 下坠滚球_Falldown
  • Hilton Sex Sound
  • Screaming Sexy Japanese Girls
  • Falling Ball Dodge
  • Scientific Calculator
  • Dice Roller
  • 躲避弹球
  • Advanced Currency Converter
  • APP Uninstaller
  • 几何战机_PewPew
  • Funny Paint
  • Spider Man
  • 蜘蛛侠

It is rather disconcerting to see such a rise in malware as of late, but that is almost unavoidable given the popularity of Android and the openness of the system. Iit is one drawback of the platform, you could argue. The scariest part is malware apps of the past have remained outside of the actual Android Market, meaning for the most part users were protected from their bad deeds. Not so much the case anymore. Be careful what you download, check the ratings and comments, and mind the developer name and permissions. If anything looks suspicious, best to hold off.

  You are doing a disservice to suggest that "reading the comments" will help spot malware. The most effective malware comes in the form of apps that do exactly what they claim to do, and do it very well, and ALSO just happen to do things you don't want.

    Until apps2sd landed in Android, the most dangerous permissions most apps asked for were:
    – modify global system settings
    – full internet access

    Lately that list must include "modify SD card contents", since any app with that permission can also modify the executables of any apps you've moved to your SD card. At the moment every one is focusing on the "front door" threat, and ignoring the many other dangers here.

    The Android security model is a broken system, plain and simple, NOT because of the OS design, but because THERE'S NO RAPID RESPONSE INFRASTRUCTURE. It took Samsung eight months to update the Epic to Android 2.2 — and then they pulled the update again. How long do you think it would take them to provide customer updates in response to an OS security hole that's being widely exploited? Here's a hint — whatever that update delay is, it's too long. This problem is multiplied over all the vendors releasing modified versions of Android.

    I've been saying it in these forums for over a year now — hardware manufacturers should stick to writing drivers and add-on apps and NEVER, EVER modify the OS. This is a point that needs a lot of publicity so that it will be driven home to both Google and the OEM's.

  @chewtoy, what are you spewing? You can't just willy nilly modify apps on the sdcard, they are encrypted and because of that they would fail to decrypt properly and they would just crash.


  12. Not advertising the app or nothing but is why I use aSpotcat

  Main story should mention that this was patched in 2.2.2 and is impossible in Gingerbread.

    Start playing the Fragmentation trumpets.

  14. @Brad you completely missed his point.

    Also, apps are not encrypted. Where did you that from? They are in the .android_secure folder which is a way of hiding in Linux. But even if they were what difference does it make? Apps are isolated from each other anyway.

  I don't actually know if the apps are encrypted or not but they are .asec and not .apk if I remember rightly and it wouldn't surprise me.
    What I do know though, is that apps are signed with a private encryption key and if they are modified they will fail to work.

  I like the android environment but it is not perfect. Google needs to screen every app available on their website for malware. The average user should not have to buy an antivirus program to scan every app they download from the market. If they sideload pirated apps or apps from a site they just found on the internet then they are to blame for any problems their phone has. Unless google wants their OS and app markets to have a reputation for malware then they need to step up and make their market safe for even the most inexperienced users.

  19. Fuck it. Lookout your going back on the Vibrant.

  There was more that got pulled then this. Publisher kingmall2010 also got a bunch pulled because of this. I have an app sexy orgasm soundboard, that he pirated into super sex sounds and all of the comments were about malicious software. I checked today and he's no longer in the market. It looked like all of his apps were pirated ones. He had around 15 or so.

  26. So what do you do if you have an app that was listed?
    Spider Man
    Advanced Currency Converter

  Apples has had to pull malicious programs too.

  Prior to this report, the only malicious apps out there were shady third party pirated apps (and apps from shady Chinese markets). Never really saw the need for an antivirus before reading this report but now I might just have to get it.
    Apple's security is not as great as you are hyping it out to be, it is always hacked at the annual Pwn2Own competition (though that is probably because it uses one of the least secure browsers known to man, Safari). Instability? Occasional force close sure but overall it is pretty stable. Fragmentation? It is a word which iPhone users recently learnt and love to use but have no idea what it means and are making it a much bigger deal than it really is. Variety is a good thing. Inconsistent software updates/inconsistent update patterns is a manufacturer-related thing, not an Android-related thing. If you get a Nexus phone, neither of those would be the case.

  Furthermore, nobody mentions the fact that the exploits used by these apps have been patched up in Android 2.2.2/2.3. Google did their part but the manufacturers/carriers did not do theirs.
    There are still Apple (original EDGE and 3G) which do not have the latest updates and security holes that can be exploited through third party apps and websites (hell, all versions of any OS have security holes which can be exploited).

    It's inevitable. Malware exist in any open system. I guess you're safe if you leave debugging off unless you are specifically needing it; since rageagainstthecage requires debugging to be on.

  32. @King Lest you forget that the iPhone used to be harvested for it’s juicy information with just a series of text messages. Regardless, you can enjoy using your device the way some rich guy tells you how to enjoy your device and I will continue to enjoy using my device the way I use it.

  35. Tell me again why a rootable phone is a good thing?

  36. One of the things I love about the android market over the apple store is the majority of apps are free, whereas you have to pay for the majority of apples.

  Fanboys aside, there is some truth to what the first post says. As an Android user you have to ask if you're OK and prepared to deal with that fact though. You also have to consider those indirectly at risk- your entire contact list.

    Another article says that any android version 2.2.2 or higher is safe. Verizon has the droid x sitting at 2.2.1. maybe they need to push an update!

  I find the UI of Android vastly superior to IOS, and I had an iPhone 3GS for 1 1/2 years and honestly did like it. I have a samsung captivate so yes slow updates are a problem, I too think google should review apps for malware before putting them on the market, now that we've seen instances of it actually getting on the market.
But with any operating system you will never truly escape the threat of malware.
    But with any operating system you will never truly escape the threat of malware.
    I also would like to see more High End Google experience phones, I would get the nexus s if it wasn't for it's lack of and sd card slot.

  "Be careful what you download, check the ratings and comments, and mind the developer name and permissions. If anything looks suspicious, best to hold off."

    ^^^ THAT.

  It's not so much the iFanboys as the iTrolls that are a pain here. We really need an iTroll filter on phandroid.

  The only secure computer (and that's exactly what we're talking about here, even if some of us make the occasional phone call with them) :-)
    is the one that is unplugged and has the battery removed.

    Because of that, users have to check what permissions each app wants, the comments, how new it is, who the developer is, etc.

    ToastNJam has a sane approach: get the apps you actually need, not every app you can find to download. Then stick with them. Unfortunately for me, I tend to fall on the other end of the spectrum. I love to explore new apps (For example, do you know how many cool carpenters level apps there are?), and because of that, I need to take all the precautions I can, including a virus checker. So far, so good. And my only sideloading experiences are with systems apps from trusted sites and developers.

    Bottom line, no matter the OS: Android, iOS, Windows, Linux, etc., and no matter the defensive tools available, only one person can keep me safe–me.

  There's another thing I always do when recommending an app that helps with the social engineering part of the problem (that is, the part that says "…they were designed to be easily confused with already popular games").

    Multiple apps can have the same name (For example, see Advanced Task Manager apps, one by ARRON LA, another by INFOLIFE LLC). So I always specify the developer as well as the app name. That helps with easily confused "near miss" app names, too. I just wish all the books/magazines would do the same.

  Any "system" running whatever OS can be compromised…

  i was an iphone user only but having an open mind i checked out android and have just bought my second android phone and sold my iphone. android has so much more.i use lookout and avg antivirus.

