Reply to topic  [ 8 posts ] 
New Android malware tricks users with real Opera Mini 
Author Message
What's a life?
User avatar

Joined: Thu Apr 23, 2009 7:56 pm
Posts: 12030
Reply with quote
Just an FYI:

http://www.zdnet.com/warning-new-android-malware-tricks-users-with-real-opera-mini-7000001586/

Quote:
Summary: Cybercriminals have created a new variant of the OpFake malware for Android that comes bundled with a legitimate version of the Opera Mini mobile browser. This helps trick users into thinking that nothing is wrong as they can simply use the real software as expected.

A new piece of malware is trying to take advantage of Opera's popularity as a mobile browser alternative on Android smartphones. Cybercriminals have created a new variant of Opfake that bundles the real Opera Mini version 6.5 so as to further mask what the malware is actually doing (earning its creators money from unsuspecting users by sending international text messages). GFI, which first discovered the malware, is calling this particular threat Trojan.AndroidOS.Generic.A. The package is named "com.surprise.me" while the file name is "opera_mini_65.apk" (both can easily be changed).

As you can see above, two sets of "Permission to Install" pages are displayed during installation. The first (above in the middle), comes from the malware itself: it asks for read and modify rights to all SMS and MMS messages, read rights to all contacts stored on the smartphone, modify or delete rights to the SD card, and so on. The second (above on the right) one appears once users agree to install the first, which is simply the permissions required for the legitimate Opera Mini browser.

This particular threat is interesting because it shows that OpFake is evolving. Instead of trying to mimic a popular app, OpFake now simply installs the real version. As a result, the user is less suspicious that something is wrong. "More than likely, users will not be aware that something might have infiltrated their phones until the bill arrives," a GFI spokesperson said in a statement.

The devil is in the details: in the background, the malicious app sends expensive international text messages to earn its creators revenue. The malicious app does the dirty work to incur costs on the victim. More specifically, here's what this particular threat does:

It sends one SMS message to a premium-rate number before it installs the legitimate Opera Mini. A command and control (C&C) server controls the message sent and the number where it is sent.
It also connects to the C&C server to retrieve data.
It reads the following stored information: Country location, Operator name, OS version, Phone type, and Device ID (IMEI).
Android lets you download and install apps from anywhere. If you want the official version of an app, however, get it from the official Google Play store. Here is the official Opera Mini link: play.google.com/store/apps/details?id=com.opera.mini.android.

_________________
www.alexsmall.co.uk

Charlie Brooker wrote:
Windows works for me. But I'd never recommend it to anybody else, ever.


Wed Jul 25, 2012 10:37 pm
Profile
What's a life?
User avatar

Joined: Thu Apr 23, 2009 8:25 pm
Posts: 10691
Location: Bramsche
Reply with quote
The big question is, with Dolphin HD, Chrome and Firefox available, why would you want Opera Mini, which does off-machine rendering and sends the rendered page as an image?

_________________
"Do you know what this is? Hmm? No, I can see you do not. You have that vacant look in your eyes, which says hold my head to your ear, you will hear the sea!" - Londo Molari

Executive Producer No Agenda Show 246


Thu Jul 26, 2012 4:31 am
Profile ICQ
What's a life?
User avatar

Joined: Fri Apr 24, 2009 10:21 am
Posts: 12700
Location: The Right Side of the Pennines (metaphorically & geographically)
Reply with quote
I guess it's a matter of personal preference.
I use Dolphin HD after having used the default browser for two years. I tried Firefox mobile, but it was dog slow.

_________________
pcernie wrote:
'I'm going to snort this off your arse - for the benefit of government statistics, of course.'


Thu Jul 26, 2012 8:57 am
Profile WWW
I haven't seen my friends in so long
User avatar

Joined: Tue May 05, 2009 3:29 pm
Posts: 7173
Reply with quote
For handsets running ICS I don't see why you'd want to run anything other than Chrome.

_________________
timark_uk wrote:
That's your problem. You need Linux. That'll fix all your problems.
Mark


Thu Jul 26, 2012 11:44 am
Profile
What's a life?
User avatar

Joined: Fri Apr 24, 2009 10:21 am
Posts: 12700
Location: The Right Side of the Pennines (metaphorically & geographically)
Reply with quote
I'm still on 2.2 (Froyo)

_________________
pcernie wrote:
'I'm going to snort this off your arse - for the benefit of government statistics, of course.'


Thu Jul 26, 2012 9:37 pm
Profile WWW
I haven't seen my friends in so long
User avatar

Joined: Thu Apr 23, 2009 7:10 pm
Posts: 5490
Location: just behind you!
Reply with quote
im on jellybean and ICS

_________________
johnwbfc wrote:
I care not which way round it is as long as at some point some sort of semi-naked wrestling is involved.

Amnesia10 wrote:
Yes but the opportunity to legally kill someone with a giant dildo does not happen every day.

Finally joined Flickr


Fri Jul 27, 2012 9:42 am
Profile
I haven't seen my friends in so long
User avatar

Joined: Fri Apr 24, 2009 7:55 am
Posts: 7935
Location: Manchester.
Reply with quote
Linux_User wrote:
For handsets running ICS I don't see why you'd want to run anything other than Chrome.

I've found that Chrome is really good... at draining the battery.
With Chrome installed I was having to charge the mobile every day. Since removing Chrome I charge it every two or three days.

_________________
okenobi wrote:
John's hot. No denying it. But he's hardly Karen now, is he ;)

John Vella BSc (Hons), PGCE - Still the official forum prankster and crude remarker :P
Sorry :roll:
I'll behave now.
Promise ;)


Fri Jul 27, 2012 1:09 pm
Profile WWW
I haven't seen my friends in so long
User avatar

Joined: Tue May 05, 2009 3:29 pm
Posts: 7173
Reply with quote
John_Vella wrote:
Linux_User wrote:
For handsets running ICS I don't see why you'd want to run anything other than Chrome.

I've found that Chrome is really good... at draining the battery.
With Chrome installed I was having to charge the mobile every day. Since removing Chrome I charge it every two or three days.

It works just fine for me on the Galaxy Nexus. :?

_________________
timark_uk wrote:
That's your problem. You need Linux. That'll fix all your problems.
Mark


Sat Jul 28, 2012 12:35 pm
Profile
Display posts from previous:  Sort by  
Reply to topic   [ 8 posts ] 

Who is online

Users browsing this forum: No registered users and 8 guests


You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum

Search for:
Jump to:  
cron
Powered by phpBB® Forum Software © phpBB Group
Designed by ST Software.