Cloned Android Apps: Symbiosis or Parasitic?
Posted by SmsMyCustomers FSecure on 8/Jul/2011 in Security Alert Log | Comments Off
There was a recent report of a malicious Android package installation being hosted on a fake “Android Market”-lookalike site, which was pushed to users from an advertisement link. The distribution strategy itself is not new. We saw variations of this happening with Google advertisements 2 years back, though in that case it was rogue or scareware that was being pushed by the advertisements. What is interesting about the case is: Android application repackaging. We’ve seen this tactic being used quite frequently in the last few months, as it seems to be the favored “quick” way for malware authors to produce new Android malware. What’s also interesting is that this seems to be a popular way for developers to produce “new”, clean applications. We’ve been seeing a rash of repackaged applications posted on the official Android Market. (Android apps are written in Java, and so they have a very low threshold for cloning, there are no real barriers to reverse engineer them.) (more…)







Recent Comments