Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Application Security

Attacks on Android Soared 40% in Q2

Despite a rise in attacks, the average number of malicious variants remains surprisingly limited, according to a report from Avast.

Cyberattacks on Android devices jumped 40% year-over-year in the second quarter fueled by cybercriminals capitalizing on increasing popularity of mobile banking.

"We are seeing a shift from PCs to mobile devices and people are using their smartphones as wallets," says Filip Chytry, director of threat intelligence at Avast. "This exponential growth in mobile attacks has been going on since 2010 or 2011 and I would expect it to continue to grow by 40% for the next several years."

During the second quarter, attacks on Android devices grew to 1.7 million per month, up from 1.2 million per month, Avast's research shows.

Patrick Hevesi, Gartner's research director of security and risk management, says he does not doubt attacks on mobile devices are rising, but he also notes it may be partially due to more companies deploying agents on their devices that can flag malicious activity.

Shift in Attacks

Rooters - malware that gives attackers root access on an Android device to spy on its users or steal their information - accounted for 22.8% of the mobile attacks Avast logged in during the second quarter. During that period, the notorious Pegasus emerged on Android.

Downloaders, which Avast characterizes as downloaded malicious apps planted on a device following a phishing attack, represented 22.8% of Android attacks in the quarter.

Although rooters and downloaders were the two most prevalent forms of cybersecurity threats in the quarter, fake apps held the number three spot at around 7% of mobile attacks, according to the report.

That's a marked shift from the 2014-2015 period when fake apps held the number one slot and accounted for 25% to 35% of mobile threats, Chytry says.

The popularity of fake apps among cybercriminals has waned as developers increasingly become more security-conscious and encrypt their source code, Chytry says. As a result, it makes it more difficult for hackers to recreate a bogus and malicious version of an app.

"Most of the companies we talk to say Trojans were the largest problem last year. Google says 54.2% of all malware were Trojans in Google Play last year and it was 77.8% for third-party stores," Gartner's Hevesi says. "But beginning in the third quarter last year, we started to see a shift."

Join Dark Reading LIVE for two days of practical cyber defense discussions. Learn from the industry’s most knowledgeable IT security experts. Check out the INsecurity agenda here.

Malicious apps are making their way into Google Play and Apple's App Store by disguising themselves as a legitimate app and keeping their exploit well-hidden until a month or two have passed, Hevesi says. That gives the app more time to gain traction among users and increase its scope of potential downloads. After time has passed, the exploit is unleashed onto the user's device.

For Avast's Chytry, the most surprising aspect of the data Avast collected in its report is that only 788 virus variations on average emerged each month during the second quarter.

"There were not a lot of variants, yet a lot of people got attacked. That tells me the attackers are well-organized because they are reusing and sharing code," Chytry says. "I would have expected 10,000 to 20,000 variants for the 1.7 million attacks."

Related Content:

Dawn Kawamoto is an Associate Editor for Dark Reading, where she covers cybersecurity news and trends. She is an award-winning journalist who has written and edited technology, management, leadership, career, finance, and innovation stories for such publications as CNET's ... View Full Bio

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
US Turning Up the Heat on North Korea's Cyber Threat Operations
Jai Vijayan, Contributing Writer,  9/16/2019
MITRE Releases 2019 List of Top 25 Software Weaknesses
Kelly Sheridan, Staff Editor, Dark Reading,  9/17/2019
Preventing PTSD and Burnout for Cybersecurity Professionals
Craig Hinkley, CEO, WhiteHat Security,  9/16/2019
Register for Dark Reading Newsletters
White Papers
Video
Cartoon Contest
Current Issue
7 Threats & Disruptive Forces Changing the Face of Cybersecurity
This Dark Reading Tech Digest gives an in-depth look at the biggest emerging threats and disruptive forces that are changing the face of cybersecurity today.
Flash Poll
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2019-14994
PUBLISHED: 2019-09-19
The Customer Context Filter in Atlassian Jira Service Desk Server and Jira Service Desk Data Center before version 3.9.16, from version 3.10.0 before version 3.16.8, from version 4.0.0 before version 4.1.3, from version 4.2.0 before version 4.2.5, from version 4.3.0 before version 4.3.4, and version...
CVE-2019-15000
PUBLISHED: 2019-09-19
The commit diff rest endpoint in Bitbucket Server and Data Center before 5.16.10 (the fixed version for 5.16.x ), from 6.0.0 before 6.0.10 (the fixed version for 6.0.x), from 6.1.0 before 6.1.8 (the fixed version for 6.1.x), from 6.2.0 before 6.2.6 (the fixed version for 6.2.x), from 6.3.0 before 6....
CVE-2019-15001
PUBLISHED: 2019-09-19
The Jira Importers Plugin in Atlassian Jira Server and Data Cente from version with 7.0.10 before 7.6.16, from 7.7.0 before 7.13.8, from 8.1.0 before 8.1.3, from 8.2.0 before 8.2.5, from 8.3.0 before 8.3.4 and from 8.4.0 before 8.4.1 allows remote attackers with Administrator permissions to gain rem...
CVE-2019-16398
PUBLISHED: 2019-09-19
On Keeper K5 20.1.0.25 and 20.1.0.63 devices, remote code execution can occur by inserting an SD card containing a file named zskj_script_run.sh that executes a reverse shell.
CVE-2019-11779
PUBLISHED: 2019-09-19
In Eclipse Mosquitto 1.5.0 to 1.6.5 inclusive, if a malicious MQTT client sends a SUBSCRIBE packet containing a topic that consists of approximately 65400 or more '/' characters, i.e. the topic hierarchy separator, then a stack overflow will occur.