Tuesday, October 24, 2017
Search
  
Submit your own News for
inclusion in our Site.
Click here...
Breaking News
Apple, Samsung Heading to Court Again
Apple Praises TSMC's Investments, Says iPhones Will be AI an Platform
ARM Boosts IoT Security With Platform Security Architecture
Kaspersky Lab Seeks To Restore Reliability By Opening Software to Review
Pay with Google Speeds Up Checkout
Tesla Said to Set up China Plant
ASUS VivoBook E203 Windows 10 S Laptop Now Available for $229
Sony Releases 7.42 Effective Megapixel Stacked CMOS Image Sensor for Automotive Cameras
Active Discussions
Which of these DVD media are the best, most durable?
How to back up a PS2 DL game
Copy a protected DVD?
roxio issues with xp pro
Help make DVDInfoPro better with dvdinfomantis!!!
menu making
Optiarc AD-7260S review
cdrw trouble
 Home > News > Mobiles > Android...
Last 7 Days News : SU MO TU WE TH FR SA All News

Wednesday, January 13, 2016
Android Trojan Steals Passwords Sent Through Voice Calls


In the last quarter of 2015,an information stealing Android threat - detected by Symantec as Android.Bankosy - added functionality to its code that can enable it to deceive voice call-based two-factor authorization (2FA) systems.

In a typical 2FA system, the second factor - normally a generated one-time passcode (OTP) - is sent to the user’s registered mobile number through short messaging service (SMS). In the past, we have seen several cases where the malware installed on the victim’s device snooped on or intercepted the incoming SMS containing the OTP. To improve the security of OTP delivery, some financial organizations started delivering OTP through voice calls instead of SMS. Of course, malware creators have already devised ways to take advantage of this development.

According to Symantec, once the Android.Bankosy malware is installed on the victim’s device, it opens a back door, collects a list of system-specific information, and sends it to the command and control (C&C) server to register the device and then get a unique identifier for the infected device. If the registration is successful, it uses the received unique identifier to further communicate with the C&C server and receive commands.

Most of the commands supported by the malware are common and trivial for typical back door or financial Trojans, such as intercepting incoming SMS, deleting SMS messages, wiping the data, etc. Symantec says that the most relevant for Android.Bankosy is call_forwarding; when this command is received by the malware from the C&C server, it executes a payload to enable call forwarding.

The back door also has support for disabling and enabling silent mode, in addition to locking the device, so that the victim is not alerted during an incoming call.

Once the unconditional call forwarding is set on the victim’s device, the attacker - who has already stolen the victim’s credentials (the first factor in two-factor authentication and authorization) - can then initiate a transaction. As part of the design, when the system demands the victim to enter the second factor (i.e., the authorization token sent through a voice call), the attacker will get the call through call forwarding and enter the second factor as well to complete the transaction.

To protect against this kind of threat on mobile devices, Symantec recommends users observe the following security best practices:

  • Keep your software up to date
  • Refrain from downloading apps from unfamiliar sites
  • Only install apps from trusted sources
  • Pay close attention to the permissions requested by an app
  • Install a suitable mobile security app, such as Norton, in order to protect your device and data
  • Make frequent backups of important data




Previous
Next
LG To Invest Additional $435 Million In Solar Cell Production        All News        Hitachi-LG Data Storage Joins Microsoft’s Windows Rally Program
Samsung Announces Mass Production of 2nd Generation 14-Nanometer FinFET Logic Process Technology     Mobiles News      Qualcomm and TDK Form Joint Venture to Provide RF Front-End Solutions for Mobiles

Get RSS feed Easy Print E-Mail this Message

Related News
Google Assistant is now on Android TV
Google Teams With Xiaomi in Dual-camera M1 A1 Smartphone
Android Oreo is Rolling Out
Cloak and Dagger Security Hole in Android Discovered
Google I/O: Google Digital Assistant Coming to iPhone, Android O, Android Go, New TPU and VR
Audi and Volvo to Use Android Auto in Upcoming Cars
Google To Release Android Updates Faster With Project Treble
Apple Pay, Samsung Pay and Android Pay Set To Expand This Year
Google Introduces Android Patent Licensing Initiative - PAX
Google Plans Faster Updates To Keep Android Phones Safe
Android O Brings Better Battery Life and Notifications
Google Family Link app Will Help You Monitor Your Kid's Android Device

Most Popular News
 
Home | News | All News | Reviews | Articles | Guides | Download | Expert Area | Forum | Site Info
Site best viewed at 1024x768+ - CDRINFO.COM 1998-2017 - All rights reserved -
Privacy policy - Contact Us .