Connect with us

Hi, what are you looking for?

HEADLINES

Old Android devices at risk from automatically downloaded and executed malware

While observing the activity of several cybercriminal groups, Kaspersky Lab researchers have spotted unusual activity in a malicious script, on an infected website, which is putting Android users at risk.

While observing the activity of several cybercriminal groups, Kaspersky Lab researchers have spotted unusual activity in a malicious script, on an infected website, which is putting Android users at risk. 

Android

The script usually activates the download of Flash exploits, to attack Windows-users. The script is a set of special instructions for execution in the browser, embedded in the code of the infected website.

However at some point it has been changed so it can check the type of device its victims are using, searching specifically for Android version 4 and older. Spotting the danger, Kaspersky Lab experts decided to delve deeper.

Infecting an Android device is much harder for criminals then infecting a Windows PC. The Windows OS – and a lot of widespread applications for it – contains vulnerabilities that allow malicious code to be executed without any interactions with a user.

This is not generally the case with the Android OS, as any application installation requires confirmation from the owner of an Android device. However, vulnerabilities in the OS can be exploited to bypass this restriction. And, as our researchers discovered during their investigation, this does happen.   

Advertisement. Scroll to continue reading.

The first script was discovered while it was looking for devices operating on the old versions of Android OS. Two more suspicious scripts were also detected subsequently.

The first one is able to send an SMS to any mobile number, while the other creates malicious files on the SD-card of the attacked device. That malicious file is a Trojan, and it has the ability to intercept and send SMS messages.

Both malicious scripts are able to perform actions independently from the Android user: you would only need to occasionally visit an infected website, to be compromised.

This was made possible because cybercriminals have utilized exploits to several vulnerabilities in Android versions 4.1.x and older – CVE-2012-6636, CVE-2013-4710 and CVE-2014-1939 in particular.

All three vulnerabilities were patched by Google between 2012 and 2014; but the risk of their exploitation still exists.

Advertisement. Scroll to continue reading.

For example, because of the Android ecosystem characteristics, many vendors producing Android-based devices are releasing the necessary security updates too slowly. Some don’t release updates at all because of the technical obsoleteness of a particular device model.

“The exploitation techniques we’ve found during our research were nothing new but borrowed from proof of concepts, previously published by white hat researchers. This means that vendors of Android devices should account for the fact that the publication of PoCs would inevitably lead to the appearance of “armed” exploits. Users of these devices deserve to be protected with corresponding security updates, even if the devices are no longer being sold at the time,” said Victor Chebyshev, security expert at Kaspersky Lab.

In order to protect yourself from drive-by attacks, Kaspersky Lab experts advise the following:

  • Keep your Android-based device software up-to-date by enabling the automatic updates function;

  • Restrict the installation of applications from alternative sources to Google Play, especially if you’re managing a collection of devices used in corporate networks;

  • Use a proven security solution. Kaspersky Internet Security for Android and Kaspersky Security for Mobile with Mobile Device Management are capable of detecting changes on the SD-card of device in real time, and thus protects users against the drive-by attacks described above.

Advertisement
Advertisement
Advertisement

Like Us On Facebook

You May Also Like

HEADLINES

Maya has already integrated National ID eVerify, the Philippine Statistics Authority’s identity-verification service, into its onboarding process. Since early this year, eligible customers have been...

HEADLINES

In 2025 alone, Converge denied nearly 12 billion entry requests to websites hosting dangerous, inappropriate, and harmful content that attempted to pass through its...

HEADLINES

The announcement represents one of the first major third-party technology integrations following the launch of Sophos Fusion, demonstrating Sophos' commitment to an open ecosystem...

HEADLINES

APAC consumers are more concerned about digital tech usage for crime than consumers globally (35% vs 32%). The awareness is highest in Thailand (39%),...

HEADLINES

“It is the time for Radenta to demonstrate that it is strongly committed to protecting client data,” remarks Nereo Bolante, Co-Director, Radenta Ethics, Compliance, and Governance Team...

HEADLINES

Attackers are operationalizing artificial intelligence (AI) to collapse attack workflows from weeks to days. The report finds that AI’s most immediate impact on cybercrime...

HEADLINES

In July 2026, researchers from the Kaspersky Global Research and Analysis Team (GReAT) team identified a new campaign, dubbed GoSerpent, representing a sophisticated and...

HEADLINES

The prominence of identity attacks in ransomware indicates a shift in method, as attackers increasingly recognize identity as a key component in ransomware delivery....

Advertisement