Subscribe
About
  • Home
  • /
  • Malware
  • /
  • Sophos reveals top five Android malware detected in the wild

Sophos reveals top five Android malware detected in the wild


Johannesburg, 15 Jun 2012

Sophos has revealed the extent of malware targeting Android mobile phones, by analysing detection statistics from its Sophos Mobile Security app.

This data was taken from installations of the application on Android smartphones and tablets in 118 different countries around the world.

SophosLabs' research revealed that the top five most commonly detected malware on Android are:

1. Andr/PJApps-C - 63.4%
2. Andr/BBridge-A - 8.8%
3. Andr/Generic-S - 6.1%
4. Andr/BatteryD-A - 4.0%
5. Andr/DrSheep-A - 2.6%

Others - 15.1%

1. Andr/PJApps-C.
When Sophos Mobile Security for Android detects an app as Andr/PJApps-C, it means it has identified an app that has been cracked using a publicly available tool.

Most commonly, these are paid-for apps that have been hacked. They are not necessarily always malicious, but are very likely to be illegal.

2. Andr/BBridge-A.
Also known as BaseBridge, this malware uses a privilege escalation exploit to elevate its privileges and install additional malicious apps onto Android devices. It uses HTTP to communicate with a central server and leaks potentially identifiable information.

These malicious apps can send and read SMS messages, potentially costing the mobile owner money. In fact, it can even scan incoming SMS messages and automatically remove warnings that you are being charged a fee for using premium rate services it has signed the user up for.

3. Andr/Generic-S.
Sophos Mobile Security generically detects a variety of families of malicious apps as Andr/Generic-S. These range from privilege escalation exploits to aggressive adware such as variants of the Android Plankton malware.

4. Andr/BatteryD-A.
This 'Battery Doctor' app falsely claims to save battery life on an Android device, but it actually sends potentially identifiable information to a server using HTTP, and aggressively displays adverts.

5. Andr/DrSheep-A.
This is an Android equivalent of the desktop tool Firesheep. It can allow malicious hackers to hijack Twitter, Facebook and LinkedIn sessions in a wireless network environment.

“The volume of malware that Sophos discovered highlights that mobile security is a real and growing problem, especially on Android,” says Brett Myroff, CEO of Sophos distributor, NetXactics.

“Criminals are creating more and more targeted malware for different platforms. Smartphone users need to realise that security is no longer limited to PCs; mobiles and tablets are also at risk if not sufficiently protected.”

A new version of Sophos' free anti-virus for Android is available from: https://play.google.com/store/apps/details?id=com.sophos.smsec

Share

NetXactics

Established in 1998, NetXactics is a South African company that specialises in sales, marketing and distribution of IT and related products. Its approach is quite unique, focusing on long-term growth coupled with exceptional customer stability. NetXactics has also been nominated as one of the top ICT companies in South Africa for four years running, and has attained a level 2 B-BBEE rating.

Editorial contacts

Adriaan du Plessis
Me Talk Pretty
(011) 782 1345
metalkpretty@telkomsa.net