Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Mobile

4/8/2020
04:00 PM
Connect Directly
Twitter
LinkedIn
RSS
E-Mail
50%
50%

'Unkillable' Android Malware App Continues to Infect Devices Worldwide

The xHelper Trojan has compromised over 55,000 devices so far, Kaspersky says.

More than 55,000 Android devices worldwide have been infected with malware that security vendor Kaspersky this week described as virtually irremovable for most users.

Kaspersky first observed the xHelper Android Trojan malware being used in mass attacks last year. Months later, the malware remains as active as ever and continues to pose a threat to Android users everywhere, according to the vendor.

Like most Android malware, xHelper is being distributed under the guise of legitimate apps — in this case, as "cleaners" and "speed-up" apps for Android smartphones. xHelper is also being downloaded by malware that comes preinstalled on Android smartphones from some device manufacturers, Kaspersky said. Users typically most at risk of their devices becoming infected are those who download apps from unofficial, third-party Android application stores.

Once installed on a device, the malware collects unique device information, such as android_id, manufacturer, model, and other data useful for targeted advertising purposes, says Igor Golovin, security expert at Kaspersky.

"xHelper significantly reduces the performance of the device and constantly displays intrusive ads," Golovin says. "Our test device turned out to be practically unusable after infection."

Mobile malware is a growing concern for enterprise organizations, especially those that permit the use of unmanaged and personally owned smartphones and tablets for work. Though attacks against mobile devices have not quite materialized in the way security experts have predicted so far, many believe it is only a matter of time before threat actors start attacking smartphone and tablet users more heavily. Numerous mobile malware tools have surfaced in recent years, including banking Trojans, spyware, tracking software, and cryptominers.

Many believe that Android devices will pose a bigger risk to enterprise security than devices running iOS because of the sheer number of malware tools targeting Android.

Particularly Persistent
What makes xHelper particularly dangerous is its ability to stay put on an infected device even if the user deletes the malware and restores the device to factory settings. Once the app is installed, it disappears and cannot be found either in the program menu or on the main screen of the device, Kaspersky said. The only place it appears is in the list of installed apps in the system settings.

The malware downloads multiple other malicious files, including one called "Triada" that enables root access to the infected device. The root access allows xHelper to install malware directly into the system partition that is mounted at device start-up, Kaspersky said.

Typically, the partition is mounted in read-only mode, but the Trojan uses its root privileges to mount it in write mode so malware programs can be installed there. All files copied to the phone are designated as "immutable," meaning they cannot be deleted even by a user with the requisite level of administrative privileges.

"This malware utilizes root access and installs additional malicious code deep into the system and its recovery mechanism," Golovin says.

Since the code is installed using root access, it cannot be removed without it. However, this access level is not normally available to users or applications on Android, Golovin notes. "Basically, this malware is protected after installation by the system itself and its security mechanisms," he says.

Detecting the malware is difficult as well because the Trojan downloads and decrypts its payloads one after another multiple times in a manner reminiscent of Russian Matryoshka nesting dolls, he says. Most of the devices on which xHelper has gained root access so far have been running Android versions 6 and 7 from Chinese manufacturers.

Kaspersky researchers have found xHelper impacting Android devices around the world. But users in some regions have been impacted more than other regions. The differences are likely due to the heavier use of devices with preinstalled malware from some manufacturers in certain countries, Golovin says.

Related Content:

A listing of free security products and services compiled for Dark Reading by Omdia analysts to help you meet the challenges of COVID-19. 

Jai Vijayan is a seasoned technology reporter with over 20 years of experience in IT trade journalism. He was most recently a Senior Editor at Computerworld, where he covered information security and data privacy issues for the publication. Over the course of his 20-year ... View Full Bio
 

Recommended Reading:

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
rhiltbrunn
50%
50%
rhiltbrunn,
User Rank: Apprentice
4/8/2020 | 9:41:03 PM
Possible fix for some who are infected with xHelp...
This is a very good article about a nasty bug on the Android platform.

There is a possible solution for some, if they are a bit technically minded, on the Malwarebytes blog site.

Here's the link:

https://blog.malwarebytes.com/android/2020/02/new-variant-of-android-trojan-xhelper-reinfects-with-help-from-google-play/

It may not be a solution to everyone's problem, but it might be a start for the more intrepid.

Cheers!
COVID-19: Latest Security News & Commentary
Dark Reading Staff 9/17/2020
Cybersecurity Bounces Back, but Talent Still Absent
Simone Petrella, Chief Executive Officer, CyberVista,  9/16/2020
Meet the Computer Scientist Who Helped Push for Paper Ballots
Kelly Jackson Higgins, Executive Editor at Dark Reading,  9/16/2020
Register for Dark Reading Newsletters
White Papers
Video
Cartoon
Current Issue
Special Report: Computing's New Normal
This special report examines how IT security organizations have adapted to the "new normal" of computing and what the long-term effects will be. Read it and get a unique set of perspectives on issues ranging from new threats & vulnerabilities as a result of remote working to how enterprise security strategy will be affected long term.
Flash Poll
How IT Security Organizations are Attacking the Cybersecurity Problem
How IT Security Organizations are Attacking the Cybersecurity Problem
The COVID-19 pandemic turned the world -- and enterprise computing -- on end. Here's a look at how cybersecurity teams are retrenching their defense strategies, rebuilding their teams, and selecting new technologies to stop the oncoming rise of online attacks.
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2020-14180
PUBLISHED: 2020-09-21
Affected versions of Atlassian Jira Service Desk Server and Data Center allow remote attackers authenticated as a non-administrator user to view Project Request-Types and Descriptions, via an Information Disclosure vulnerability in the editform request-type-fields resource. The affected versions are...
CVE-2020-14177
PUBLISHED: 2020-09-21
Affected versions of Atlassian Jira Server and Data Center allow remote attackers to impact the application's availability via a Regex-based Denial of Service (DoS) vulnerability in JQL version searching. The affected versions are before version 7.13.16; from version 7.14.0 before 8.5.7; from versio...
CVE-2020-14179
PUBLISHED: 2020-09-21
Affected versions of Atlassian Jira Server and Data Center allow remote, unauthenticated attackers to view custom field names and custom SLA names via an Information Disclosure vulnerability in the /secure/QueryComponent!Default.jspa endpoint. The affected versions are before version 8.5.8, and from...
CVE-2020-25789
PUBLISHED: 2020-09-19
An issue was discovered in Tiny Tiny RSS (aka tt-rss) before 2020-09-16. The cached_url feature mishandles JavaScript inside an SVG document.
CVE-2020-25790
PUBLISHED: 2020-09-19
** DISPUTED ** Typesetter CMS 5.x through 5.1 allows admins to upload and execute arbitrary PHP code via a .php file inside a ZIP archive. NOTE: the vendor disputes the significance of this report because "admins are considered trustworthy"; however, the behavior "contradicts our secu...