Please, just stop downloading apps from unofficial stores: Android users hit with 'unkillable malware'
- Reference: 1586329445
- News link: https://www.theregister.co.uk/2020/04/08/xhelper_android_malware/
- Source link:
Known as xHelper, the malware has been spreading mainly in Russia, Europe, and Southwest Asia on Android 6 and 7 devices (which while old and out of date, make up around 15 per cent of the current user base) for the past year from unofficial app stores. Once on a gizmo, it opens a backdoor, allowing miscreants to spy on owners, steal their data, and cause mischief.
It has only recently been picked apart by Kaspersky Lab bods, and what makes the malware particularly nasty, the researchers say, is how it operates on multiple layers on the tablets and handsets it infects.
"The main feature of xHelper is entrenchment," [1]explained Igor Golovin on Tuesday. "Once it gets into the phone, it somehow remains there even after the user deletes it and restores the factory settings."
When the malware is downloaded under the guise of a legit device "cleaning" app, it seems simple enough. A "dropper" trojan is pulled down from the internet, which collects device information and downloads and runs another trojan, which, in turn, downloads a set of exploit code that, when run, grants the malware root privileges on the device. This exploit code targets security vulnerabilities seemingly prevalent in Chinese-made Android 6 and 7 devices.
Each of these malware downloads, by the way, are nested within a succession of folders hidden further away from security tools to make them harder to spot.
More than a billion hopelessly vulnerable Android gizmos in the wild that no longer receive security updates – research [2]READ MORE
"Malicious files are stored sequentially in the app’s data folder, which other programs do not have access to," explained Golovin. "This matryoshka-style scheme allows the malware authors to obscure the trail and use malicious modules that are known to security solutions."
Armed with its powerful root privileges, the malware mounts the operating system partition with write access enabled – which isn't normally done – allowing the software nasty to copy itself there. The malware changes the code for the mount() function in the system's shared libc core library to prevent the user and apps from doing the same in the future to delete the malicious program, thus locking itself in and locking victims out.
This means it can make sure it runs from every system startup and is reinstalled from the system partition if the device is factory reset.
To make things worse, the malware downloads and installs more nasties and removes various bits of the system. Not surprisingly, Golovin says, this makes the infection nearly impossible to completely remove.
"Simply removing xHelper does not entirely disinfect the system," said the egghead. "The program com.diag.patches.vm8u, installed in the system partition, reinstalls xHelper and other malware at the first opportunity."
If you catch this malware, you can try to restore the vandalized libc in Android recovery mode, and then remount the system partition in write mode, and remove the malware yourself.
The best thing to do, though, is go a step further than a factory reset, and erase the flash memory completely, including the system partition, and put in a fresh clean copy. "If you have Recovery mode set up on your Android smartphone," said Golovin, "you can try to extract the libc.so file from the original firmware and replace the infected one with it, before removing all malware from the system partition. However, it’s simpler and more reliable to completely reflash the phone."
Even better advice is to avoid downloading any suspicious apps from the Google Play Store, just to be safe, and definitely don't use unauthorized third-party stores at all. ®
Sponsored: [3]Choosing A Low-Code Vendor
[1] https://securelist.com/unkillable-xhelper-and-a-trojan-matryoshka/96487/
[2] https://www.theregister.co.uk/2020/03/06/1_billion_vulnerable_android_devices_which/
[3] https://go.theregister.co.uk/tl/1936/-8579/choosing-a-low-code-vendor?td=wptl1936
Armed with its powerful root privileges....
I guess Android's security model still needs work if something can waltz in from outside and assume root privilege. I am of the opinion that the "no user has admin authority" model has an inherent flaw to it. The mechanisms of privilege escalation and control do not get exercised enough to iron the bugs out.
"and assume root privilege"
No, it has to exploit security holes in Android 6 and 7, which are old and out of date, to achieve root.
C.
Re: "and assume root privilege"
...and user rooted devices will block unknown apps by default.
Re: "and assume root privilege"
"and user rooted devices will block unknown apps by default"
you sure it's not the opposite (or were you being snarky)?
A normal "non-rooted" device blocks un-blessed applications by default, requiring you to jump through a hoop or two to install the potentially "dirty" ones. Some older 'droid versions were actually LESS convenient for doing this, at least on the versions I've worked with [I've had to do it for development stuff a while back, put APK up someplace, have people install it, etc.]. Newer ones have different hoops when you download, but just an extra "yes I want to do this" step rather than changing the default setting to allow 'foreign' APKs or whatever. It's been a while since I did it last... [online instructions if I forget]
But yeah any downloaded APK is a potential disaster for the person installing. The idea that a factory reset does NOT get rid of this particular malware is disturbing. Not sure how to EASILY do a complete re-flash though. It sounds like it would require more than an average tech... [maybe time to research doing that - I never went so far as to figure out how to do a complete re-flash on a 'droid device]
maybe future 'droid devices will need to ship with actual ROM (and not a potentially writable image) for a PROPER factory reset.
/me considers investigating how a debug USB cable might make this a little easier to deal with...
(I obviously STILL have a lot to learn about these things)
and yet - the absolute LAST thing we should want to see is an Apple-like (paywall and/or censor-wall) *STRANGLEHOLD* on what you can or cannot install... _ESPECIALLY_ for independent developers!
nice to see a breakdown of how it persists
Earlier reports seem to have not known how factory reset works and how little it actually does. If you're not into flashing 3rd party OS images I guess you just wouldn't think about recovery mode and reflashing - nuking the partitions from orbit.
Re: nice to see a breakdown of how it persists
yes - it doesn't sound trivial at all. Maybe I should get another el-cheapo slab and try upgrading the old one, to improve my 'droid skills.
Credit where credit is due
They may be scum, but you have to give them credit for knowing exactly how to completely pwn the phone system internals.
That is an amount of analysis and reverse engineering that is impressive.
So, congratulations. Now where's that noose ?