Attacks/Breaches
8/13/2013
11:33 AM
50%
50%

Android Malware Being Delivered Via Ad Networks

Attackers are using mobile ad network software installed on smartphones to push malicious JavaScript and take control of devices.

Beware active attacks that are using mobile advertising networks to deliver malware that's able to fully compromise Android devices.

So warned researchers at next-generation firewall vendor Palo Alto, who said they've discovered a series of attacks that have been serving up malicious code by hacking into an ad network's software development kit (SDK). Developers add these SDKs to their Android apps to tie into mobile advertising networks and earn referral fees.

The malware recovered by Palo Alto compromises an Android's SMS capabilities, allowing attackers to send and receive SMS messages without the user's knowledge. Attackers have used that functionality to sign people up for premium SMS services that drain subscribers' accounts and enrich the service operators -- typically the attackers themselves or their business partners. The SMS communications channel also gives attackers basic command-and-control functionality, meaning they could use compromised devices as part of a bigger Android botnet.

[ Google Play can be a tough neighborhood. Read Google Play: Beware Android Adware Infestation. ]

The Android mobile ad network attacks are unusual because the majority of online attacks today either target browser vulnerabilities as a stepping stone to installing malware or rely on phishing attacks and tricking users into executing malicious attachments. But by targeting an ad-network SDK, hackers can enjoy direct access to the device. "That's kind of a built-in backdoor into the application, and when a mobile ad network starts serving bad content, it shifts to become a botnet that is suddenly serving malicious content," explained Wade Williamson, a senior security analyst at Palo Alto, speaking by phone. "But the difference is there's no exploit needed, no bait and switch needed, because you already have this hook built into the application."

The threat mirrors the use of ad networks to create browser-based botnets. That vulnerability was detailed earlier this month at the Black Hat information security conference in Las Vegas by WhiteHat Security CTO Jeremiah Grossman, and Matt Johansen, who manages the firm's threat research center. The pair demonstrated how a would-be attacker could create a fake online advertisement with malicious JavaScript embedded, which would allow them to connect hundreds or thousands of PCs at once to a targeted website, thus creating a denial of service.

But the threat discovered by Palo Alto differs in two significant ways: First, attackers don't need to place a fake advertisement. Instead, they can simply hack into an advertising network, and that's assuming it's not a network that they -- or their business partners -- don't already control. Second, Palo Alto's researchers weren't theorizing. To date, they've seen seven infections, all in Asia, that have resulted from hacking into mobile advertising networks. The company, which builds Android APK file security check software, said none of the malware it recovered was recognized as such by Android antivirus scanners.

The ad-network-delivered malware recovered by Palo Alto is stealthy and doesn't attempt to trick a user into installing it immediately. "The malware itself was smart enough so that once it was delivered through the ad network, it wouldn't pop up and say, 'User, do you want to install me?" said Williamson. "It would just sit there and run in current memory, and it could do that, because think of how rarely we do a hard reset on our phones."

How can attackers who inject malicious code directly into Android devices via ad-network SDKs be stopped? One approach would be to sandbox all Android (APK) files so they can't touch other apps or unapproved device functionality. Another remedy might be to have Google not only vouch for the health of an app, as it does when offering them via Google Play, but instead maintain health checks for any advertising networks that the app touches.

In other words, Google could provide an "approved ecosystem" seal, said Williamson. "The challenge, I think, is that almost no one who buys mobile apps understands how that app relies on the ad network for its financial security," he said. "So it's going to require some user education into why an approved ad network matters."

Unfortunately, not all mobile ad networks can be trusted. In April, for example, Marc Rogers, principal security researcher at Lookout Mobile Security, reported finding BadNews, which masquerades as an innocent, if somewhat aggressive advertising network, according to a blog he posted at the time. All told, Lookout found 32 different apps from four different developer accounts that included the BadNews SDK and were available for download from Google Play.

"This is one of the first times that we've seen a malicious distribution network clearly posing as an ad network," Rogers said at the time. "Because it's challenging to get malicious bad code into Google play, the authors of BadNews created a malicious advertising network as a front that would push malware out to infected devices at a later date in order to pass the app scrutiny."

Comment  | 
Print  | 
More Insights
Comments
Threaded  |  Newest First  |  Oldest First
DerekC632
50%
50%
DerekC632,
User Rank: Apprentice
8/13/2013 | 11:19:37 PM
re: Android Malware Being Delivered Via Ad Networks
This has been a problem for a while, but it's only getting talked about now. With a few exceptions, like Airpush, most ad networks take very few precautions to make sure theirs ads don't carry malware. Every ad network needs to take filtering very, very seriously. If not, this is going to start negatively effecting mobile advertising's future - http://www.examiner.com/articl...
Register for Dark Reading Newsletters
Dark Reading Live EVENTS
INsecurity - For the Defenders of Enterprise Security
A Dark Reading Conference
While red team conferences focus primarily on new vulnerabilities and security researchers, INsecurity puts security execution, protection, and operations center stage. The primary speakers will be CISOs and leaders in security defense; the blue team will be the focus.
White Papers
Video
Cartoon Contest
Write a Caption, Win a Starbucks Card! Click Here
Latest Comment: No, no, no! Have a Unix CRON do the pop-up reminders!
Current Issue
Security Vulnerabilities: The Next Wave
Just when you thought it was safe, researchers have unveiled a new round of IT security flaws. Is your enterprise ready?
Flash Poll
The Impact of a Security Breach 2017
The Impact of a Security Breach 2017
Despite the escalation of cybersecurity staffing and technology, enterprises continue to suffer data breaches and compromises at an alarming rate. How do these breaches occur? How are enterprises responding, and what is the impact of these compromises on the business? This report offers new data on the frequency of data breaches, the losses they cause, and the steps that organizations are taking to prevent them in the future.
Slideshows
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2017-0290
Published: 2017-05-09
NScript in mpengine in Microsoft Malware Protection Engine with Engine Version before 1.1.13704.0, as used in Windows Defender and other products, allows remote attackers to execute arbitrary code or cause a denial of service (type confusion and application crash) via crafted JavaScript code within ...

CVE-2016-10369
Published: 2017-05-08
unixsocket.c in lxterminal through 0.3.0 insecurely uses /tmp for a socket file, allowing a local user to cause a denial of service (preventing terminal launch), or possibly have other impact (bypassing terminal access control).

CVE-2016-8202
Published: 2017-05-08
A privilege escalation vulnerability in Brocade Fibre Channel SAN products running Brocade Fabric OS (FOS) releases earlier than v7.4.1d and v8.0.1b could allow an authenticated attacker to elevate the privileges of user accounts accessing the system via command line interface. With affected version...

CVE-2016-8209
Published: 2017-05-08
Improper checks for unusual or exceptional conditions in Brocade NetIron 05.8.00 and later releases up to and including 06.1.00, when the Management Module is continuously scanned on port 22, may allow attackers to cause a denial of service (crash and reload) of the management module.

CVE-2017-0890
Published: 2017-05-08
Nextcloud Server before 11.0.3 is vulnerable to an inadequate escaping leading to a XSS vulnerability in the search module. To be exploitable a user has to write or paste malicious content into the search dialogue.