{"id":4117,"date":"2014-02-25T14:52:03","date_gmt":"2014-02-25T06:52:03","guid":{"rendered":"http:\/\/www.upgrademag.com\/web\/?p=4117"},"modified":"2014-02-25T14:53:40","modified_gmt":"2014-02-25T06:53:40","slug":"android-os-favorite-target-malware-developers","status":"publish","type":"post","link":"http:\/\/www.upgrademag.com\/web\/2014\/02\/25\/android-os-favorite-target-malware-developers\/","title":{"rendered":"Android OS is favorite target of malware developers"},"content":{"rendered":"<p><strong>Year 2013 was a bumper crop for malware targeting mobile devices. Android was the dominant platform of choice for malware developers, representing 96.5% of all mobile malware infections, according to a whitepaper released by Fortinet\u2019s FortiGuard Labs. Symbian was a distant second at 3.45% and iOS, BlackBerry, PalmOS and Windows together don\u2019t even warrant 1%.<\/strong><\/p>\n<p>\u201cThe rapid growth of malware targeting Android continues to be of concern to system administrators who have implemented a mobile device strategy on their networks,\u201d said Axelle Apvrille, senior mobile antivirus researcher with Fortinet&#8217;s FortiGuard Labs. \u201cFortiGuard Labs detected over 1,800 new distinct families of viruses in the past year, and the majority of those are targeting Google\u2019s Android platform. Looking at the growth of Android malware, we can see that there is much to be concerned about in 2014. The growth shows no signs of slowing; in fact, the growth seems to be accelerating. As more Android-based devices are purchased and taken online, the opportunities for attackers to infect increases as well.\u201d<\/p>\n<p>While attacks on platforms such as Symbian wane, attackers have made Android the number one mobile target. The NewyearL.B Android malware, which was bundled inside seemingly harmless downloads like a flashlight application, continued to target millions of devices and was the number one mobile malware family seen all year. Unwitting or unaware users looking to try out the latest games or apps find themselves unknowingly sharing a wealth of personal information with an attacker, leading to obtrusive advertisements and other negative effects, such as allowing NewyearL.B permission to add and remove system icons and modify and delete the contents of any external storage. And the distribution of Android malware continues to accelerate.<\/p>\n<p>\u201cClearly cybercriminals are putting a substantial amount of effort into churning out hundreds of thousands of new variants daily in the hopes that some of them will be successfully implanted on a target device,\u201d Apvrille said.<\/p>\n<p><strong>Top 10 Mobile Malware Families based on Reported Incidents<\/strong><br \/>\n1.\u00a0\u00a0\u00a0\u00a0\u00a0 Android\/NewyearL.B<br \/>\n2.\u00a0\u00a0\u00a0\u00a0\u00a0 Android\/DrdLight.D<br \/>\n3.\u00a0\u00a0\u00a0\u00a0\u00a0 Android\/DrdDream<br \/>\n4.\u00a0\u00a0\u00a0\u00a0\u00a0 Android\/SMSSend Family<br \/>\n5.\u00a0\u00a0\u00a0\u00a0\u00a0 Android\/OpFake Family<br \/>\n6.\u00a0\u00a0\u00a0\u00a0\u00a0 Android\/Basebridge.A<br \/>\n7.\u00a0\u00a0\u00a0\u00a0\u00a0 Android\/Agent Family<br \/>\n8.\u00a0\u00a0\u00a0\u00a0\u00a0 Android\/AndCom.A<br \/>\n9.\u00a0\u00a0\u00a0\u00a0\u00a0 Android\/Lotoor Family<br \/>\n10.\u00a0 Android\/Qdplugin.A<\/p>\n<p><strong>ZeroAccess: The Most Prolific Botnet of the Year<\/strong><br \/>\nEarlier in 2013, FortiGuard Labs reported on the ZeroAccess botnet and how its controllers were systematically adding about 100,000 new infections weekly, leading researchers to believe that the person or persons behind it were not only paying a substantial amount of money weekly to generate new affiliate infections, but that they were able to make a significant amount of money doing so.<\/p>\n<p>\u201cLike other cybercriminals, ZeroAccess\u2019s owners have taken pages from the playbooks of legitimate businesses and made successful attempts to diversify their income generation,\u201d said Richard Henderson, security strategist with Fortinet\u2019s FortiGuard Labs. \u201cWe saw 32- and 64-bit versions of ZeroAccess being used to commit click fraud, search engine poisoning and to mine Bitcoin. With the dramatic rise in Bitcoin value over 2013, it\u2019s likely that the owners of ZeroAccess have profited substantially on the backs of their victims.\u201d<\/p>\n<p><strong>Top 10 Botnets Based on Reported Incidents with Percentage of Overall Dominance<\/strong><br \/>\n1.\u00a0\u00a0\u00a0\u00a0\u00a0 ZeroAccess (88.65%)<br \/>\n2.\u00a0\u00a0\u00a0\u00a0\u00a0 Andromeda (3.76%)<br \/>\n3.\u00a0\u00a0\u00a0\u00a0\u00a0 Jeefo (3.58%)<br \/>\n4.\u00a0\u00a0\u00a0\u00a0\u00a0 Smoke (2.03%)<br \/>\n5.\u00a0\u00a0\u00a0\u00a0\u00a0 Morto (0.91%)<br \/>\n6.\u00a0\u00a0\u00a0\u00a0\u00a0 Mariposa (0.43%)<br \/>\n7.\u00a0\u00a0\u00a0\u00a0\u00a0 Waledac (0.18%)<br \/>\n8.\u00a0\u00a0\u00a0\u00a0\u00a0 IMDDOS (0.18%)<br \/>\n9.\u00a0\u00a0\u00a0\u00a0\u00a0 Mazben (0.15%)<br \/>\n10.\u00a0 Torpig (0.10%)<\/p>\n<p><strong>ZeuS is Still the King of the Malware Hill<\/strong><br \/>\nIn terms of general PC malware, the ZeuS trojan took the top spot in 2013, with over 20 million attempts to infect FortiGate-protected networks. ZeuS first showed up on computers in 2007 and has been a thorn in the side of Internet users ever since. The 2011 leak of ZeuS\u2019 source code led to an explosion of copy cat variants by aspiring cybercriminals looking to make their fortunes on the backs of innocent victims.<\/p>\n<p>\u201cAn interesting and nefarious development late in 2013 saw ZeuS infections being used in a new way,\u201d Henderson continued. \u201cWhile ZeuS was often used as a financial trojan, a significant number of ZeuS infections were used to deliver and execute the Cryptolocker ransomware. Cryptolocker put a new spin on ransomware in that it used uniquely generated cryptographic key pairs to fully encrypt the contents of a victim\u2019s computer, and any mapped drive the victim had the ability to write to. Cryptolocker would then inform the victim they had a short period of time to pay a significant ransom \u2212 sometimes as much as a few hundred dollars, and typically only paid using the Bitcoin cryptocurrency \u2212 before the encryption key used to encrypt the victim\u2019s computer was deleted, making the victim\u2019s files completely unrecoverable.\u201d<\/p>\n<p>Victims ranged from home users losing thousands of personally significant files such as photographs and home movies, to businesses of all sizes and public agencies. Cryptolocker was also seen to infect users via other methods, including infected flash drives, often in combination with fake program activation tools commonly spread through file sharing sites and through infected email attachments.<br \/>\n<strong>\u00a0<\/strong><br \/>\n<strong>Top 10 Malware Families Basis Based on Number of Reported Incidents<\/strong><br \/>\n1.\u00a0\u00a0\u00a0\u00a0\u00a0 W32\/ZeuS(Zbot) Family<br \/>\n2.\u00a0\u00a0\u00a0\u00a0\u00a0 W32\/Tepfer Family<br \/>\n3.\u00a0\u00a0\u00a0\u00a0\u00a0 JS\/FBJack.A<br \/>\n4.\u00a0\u00a0\u00a0\u00a0\u00a0 PDF\/Script.JS<br \/>\n5.\u00a0\u00a0\u00a0\u00a0\u00a0 W32\/ZeroAccess Family<br \/>\n6.\u00a0\u00a0\u00a0\u00a0\u00a0 W32\/Kryptik Family<br \/>\n7.\u00a0\u00a0\u00a0\u00a0\u00a0 JS\/IFrame Family<br \/>\n8.\u00a0\u00a0\u00a0\u00a0\u00a0 W32\/Yakes.B<br \/>\n9.\u00a0\u00a0\u00a0\u00a0\u00a0 X97M\/Agent.F<br \/>\n10.\u00a0 W32\/Blocker Family<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Android was the dominant platform of choice for malware developers in 2013, representing 96.5% of all mobile malware infections, according to a new report.<\/p>\n","protected":false},"author":6,"featured_media":4118,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[11,10,9,19,13],"tags":[3361,169,303,103,393,859],"class_list":["post-4117","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-android","category-ios","category-apps","category-headlines","category-microsoft","tag-android","tag-fortinet","tag-ios-2","tag-malware","tag-research","tag-windows"],"_links":{"self":[{"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/posts\/4117","targetHints":{"allow":["GET"]}}],"collection":[{"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/users\/6"}],"replies":[{"embeddable":true,"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/comments?post=4117"}],"version-history":[{"count":0,"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/posts\/4117\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/media\/4118"}],"wp:attachment":[{"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/media?parent=4117"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/categories?post=4117"},{"taxonomy":"post_tag","embeddable":true,"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/tags?post=4117"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}