Threat Intelligence

8/10/2017
03:54 PM
50%
50%

SonicSpy Authors Spin Out Over 1,000 Spyware Apps

The actors behind this new malware family created a sizable selection of malicious apps in just over seven months, some of which appeared on Google Play.

A new variant of SonicSpy was recently discovered on Google Play, one of over a thousand apps that have been tied to the malware family since February, according to researchers from Lookout published in a blog post today.

The SonicSpy variant most recently found on the Google Play app store is called Soniac and is marketed as a messaging app. Although Soniac will perform some messaging functions, through the use of a customized version of Telegram, its author's intent is to hijack a user's Android phone. Some of Soniac's capabilities include silently recording audio, taking photos, making outbound calls, and sending text messages to phone numbers that the attacker specifies, according to Lookout.

Samples of SonicSpy feature a number of similarities to another malware family called SpyNote, which emerged in mid-2016, according to Lookout. These similarities include running on a non-standard 2222 port, relying heavily on dynamic DNS services, and sharing similar code traits. As a result, researchers believe the same actor may be involved with both malware families.

Lookout researchers believe the actors behind SonicSpy may be prolific because they are using an automated process to churn out the variants, the company says.

Read more about SonicSpy here

Dark Reading's Quick Hits delivers a brief synopsis and summary of the significance of breaking news events. For more information from the original source of the news item, please follow the link provided in this article. View Full Bio

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
RyanSepe
50%
50%
RyanSepe,
User Rank: Ninja
8/11/2017 | 6:22:41 AM
Intensive App Review
This is why without an intensive app review process, items like this will continue to abound. Being able to automate variants renders technology based review ineffective without any type of heuristics.
Higher Education: 15 Books to Help Cybersecurity Pros Be Better
Curtis Franklin Jr., Senior Editor at Dark Reading,  12/12/2018
Worst Password Blunders of 2018 Hit Organizations East and West
Curtis Franklin Jr., Senior Editor at Dark Reading,  12/12/2018
2019 Attacker Playbook
Ericka Chickowski, Contributing Writer, Dark Reading,  12/14/2018
Register for Dark Reading Newsletters
White Papers
Video
Cartoon Contest
Current Issue
10 Best Practices That Could Reshape Your IT Security Department
This Dark Reading Tech Digest, explores ten best practices that could reshape IT security departments.
Flash Poll
[Sponsored Content] The State of Encryption and How to Improve It
[Sponsored Content] The State of Encryption and How to Improve It
Encryption and access controls are considered to be the ultimate safeguards to ensure the security and confidentiality of data, which is why they're mandated in so many compliance and regulatory standards. While the cybersecurity market boasts a wide variety of encryption technologies, many data breaches reveal that sensitive and personal data has often been left unencrypted and, therefore, vulnerable.
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2018-20201
PUBLISHED: 2018-12-18
There is a stack-based buffer over-read in the jsfNameFromString function of jsflash.c in Espruino 2V00, leading to a denial of service or possibly unspecified other impact via a crafted js file.
CVE-2018-20194
PUBLISHED: 2018-12-18
There is a stack-based buffer underflow in the third instance of the calculate_gain function in libfaad/sbr_hfadj.c in Freeware Advanced Audio Decoder 2 (FAAD2) 2.8.8. A crafted input will lead to a denial of service or possibly unspecified other impact because limiting the additional noise energy l...
CVE-2018-20195
PUBLISHED: 2018-12-18
A NULL pointer dereference was discovered in ic_predict of libfaad/ic_predict.c in Freeware Advanced Audio Decoder 2 (FAAD2) 2.8.8. The vulnerability causes a segmentation fault and application crash, which leads to denial of service.
CVE-2018-20196
PUBLISHED: 2018-12-18
There is a stack-based buffer overflow in the third instance of the calculate_gain function in libfaad/sbr_hfadj.c in Freeware Advanced Audio Decoder 2 (FAAD2) 2.8.8. A crafted input will lead to a denial of service or possibly unspecified other impact because the S_M array is mishandled.
CVE-2018-20197
PUBLISHED: 2018-12-18
There is a stack-based buffer underflow in the third instance of the calculate_gain function in libfaad/sbr_hfadj.c in Freeware Advanced Audio Decoder 2 (FAAD2) 2.8.8. A crafted input will lead to a denial of service or possibly unspecified other impact because limiting the additional noise energy l...