Skip to main content

Android malware begs behavioural change

posted onMarch 6, 2011
by hitbsecnews

Early last week Google removed a bunch of malicious apps, most disguised as legitimate, from the Android Market after they were found to contain malware. The malware, dubbed DroidDream, uses two exploits to steal information such as phone ID and model, and to plant a backdoor on the phone that could be used to drop further malware on the device and take it over.

"At a minimum, they have to do signature-based scanning for known malware," application security provider Veracode chief technology officer, Chris Wysopal, said. "DroidDream is now a malware kit and it would be easy for people to make variations of it and insert it into new software."

But traditional signature-based antivirus software isn't good at detecting brand new malware or existing malware that has been modified enough to slip past the antivirus programs. To catch something like DroidDream then, behavioural-based antivirus scanning should also be used, according to Wysopal.

Source

Tags

Viruses & Malware

You May Also Like

Recent News

Friday, November 29th

Tuesday, November 19th

Friday, November 8th

Friday, November 1st

Tuesday, July 9th

Wednesday, July 3rd

Friday, June 28th

Thursday, June 27th

Thursday, June 13th

Wednesday, June 12th

Tuesday, June 11th