Malicious Android Code Disguised As Images

Search
Joined
Jan 17, 2007
Messages
99,709
Tokens
A security flaw in Android means hackers can create malicious software that looks like an image.


By wrapping up a photo or graphic with malware, it can be delivered in a way which gets past security apps and the Google Bouncer security scanner.


Google kept the security flaw quiet until it had provided a patch for its software, however users who rarely update their phone's operating system are likely still at risk.


The technique works by making malicious code look like a valid image format - such as PNG or JPG - using a custom encryption package.


The flaw was detailed by researchers Axelle Apvrille and Ange Albertini on the Black Hat hacking news website.


Writing before the problem was patched they said: "Such an attack is highly likely to go unnoticed, because the wrapping Android package hardly has anything suspicious about it, and nothing about the payload leaks as it is encrypted.


"Additionally, the attack works with any payload and currently on any version of Android."


In the researchers' demonstration, a malicious application designed to steal photos, messages and other data was designed to look like an image of Darth Vader.
 

Member
Handicapper
Joined
Oct 31, 2004
Messages
44,294
Tokens
Sounds like a problem for people who don't have iPhones
It must suck to be them
 

Member
Joined
Mar 6, 2005
Messages
2,337
Tokens
hackers have been hiding code in images, on all platforms, for a long time. terrorists have been exchanging messages hidden in images for a long time as well. they would post hundreds of images in a usenet newsgroup and then direct the recipient to download the images and decipher the messages. nothing new, nothing an antivirus won't catch either.
 

Forum statistics

Threads
1,108,192
Messages
13,449,275
Members
99,400
Latest member
steelreign
The RX is the sports betting industry's leading information portal for bonuses, picks, and sportsbook reviews. Find the best deals offered by a sportsbook in your state and browse our free picks section.FacebookTwitterInstagramContact Usforum@therx.com