News: 1586329445

  ARM Give a man a fire and he's warm for a day, but set fire to him and he's warm for the rest of his life (Terry Pratchett, Jingo)

Please, just stop downloading apps from unofficial stores: Android users hit with 'unkillable malware'

(2020/04/08)


An Android malware package likened to a Russian matryoshka nesting doll has security researchers raising the alarm, since it appears it's almost impossible to get rid of.

Known as xHelper, the malware has been spreading mainly in Russia, Europe, and Southwest Asia on Android 6 and 7 devices (which while old and out of date, make up around 15 per cent of the current user base) for the past year from unofficial app stores. Once on a gizmo, it opens a backdoor, allowing miscreants to spy on owners, steal their data, and cause mischief.

It has only recently been picked apart by Kaspersky Lab bods, and what makes the malware particularly nasty, the researchers say, is how it operates on multiple layers on the tablets and handsets it infects.

"The main feature of xHelper is entrenchment," [1]explained Igor Golovin on Tuesday. "Once it gets into the phone, it somehow remains there even after the user deletes it and restores the factory settings."

When the malware is downloaded under the guise of a legit device "cleaning" app, it seems simple enough. A "dropper" trojan is pulled down from the internet, which collects device information and downloads and runs another trojan, which, in turn, downloads a set of exploit code that, when run, grants the malware root privileges on the device. This exploit code targets security vulnerabilities seemingly prevalent in Chinese-made Android 6 and 7 devices.

Each of these malware downloads, by the way, are nested within a succession of folders hidden further away from security tools to make them harder to spot.

More than a billion hopelessly vulnerable Android gizmos in the wild that no longer receive security updates – research [2]READ MORE

"Malicious files are stored sequentially in the app’s data folder, which other programs do not have access to," explained Golovin. "This matryoshka-style scheme allows the malware authors to obscure the trail and use malicious modules that are known to security solutions."

Armed with its powerful root privileges, the malware mounts the operating system partition with write access enabled – which isn't normally done – allowing the software nasty to copy itself there. The malware changes the code for the mount() function in the system's shared libc core library to prevent the user and apps from doing the same in the future to delete the malicious program, thus locking itself in and locking victims out.

This means it can make sure it runs from every system startup and is reinstalled from the system partition if the device is factory reset.

To make things worse, the malware downloads and installs more nasties and removes various bits of the system. Not surprisingly, Golovin says, this makes the infection nearly impossible to completely remove.

"Simply removing xHelper does not entirely disinfect the system," said the egghead. "The program com.diag.patches.vm8u, installed in the system partition, reinstalls xHelper and other malware at the first opportunity."

If you catch this malware, you can try to restore the vandalized libc in Android recovery mode, and then remount the system partition in write mode, and remove the malware yourself.

The best thing to do, though, is go a step further than a factory reset, and erase the flash memory completely, including the system partition, and put in a fresh clean copy. "If you have Recovery mode set up on your Android smartphone," said Golovin, "you can try to extract the libc.so file from the original firmware and replace the infected one with it, before removing all malware from the system partition. However, it’s simpler and more reliable to completely reflash the phone."

Even better advice is to avoid downloading any suspicious apps from the Google Play Store, just to be safe, and definitely don't use unauthorized third-party stores at all. ®

Sponsored: [3]Choosing A Low-Code Vendor



[1] https://securelist.com/unkillable-xhelper-and-a-trojan-matryoshka/96487/

[2] https://www.theregister.co.uk/2020/03/06/1_billion_vulnerable_android_devices_which/

[3] https://go.theregister.co.uk/tl/1936/-8579/choosing-a-low-code-vendor?td=wptl1936

Credit where credit is due

Pascal Monett

They may be scum, but you have to give them credit for knowing exactly how to completely pwn the phone system internals.

That is an amount of analysis and reverse engineering that is impressive.

So, congratulations. Now where's that noose ?

TeeCee

Armed with its powerful root privileges....

I guess Android's security model still needs work if something can waltz in from outside and assume root privilege. I am of the opinion that the "no user has admin authority" model has an inherent flaw to it. The mechanisms of privilege escalation and control do not get exercised enough to iron the bugs out.

"and assume root privilege"

diodesign

No, it has to exploit security holes in Android 6 and 7, which are old and out of date, to achieve root.

C.

Re: "and assume root privilege"

Paul Shirley

...and user rooted devices will block unknown apps by default.

Re: "and assume root privilege"

bombastic bob

"and user rooted devices will block unknown apps by default"

you sure it's not the opposite (or were you being snarky)?

A normal "non-rooted" device blocks un-blessed applications by default, requiring you to jump through a hoop or two to install the potentially "dirty" ones. Some older 'droid versions were actually LESS convenient for doing this, at least on the versions I've worked with [I've had to do it for development stuff a while back, put APK up someplace, have people install it, etc.]. Newer ones have different hoops when you download, but just an extra "yes I want to do this" step rather than changing the default setting to allow 'foreign' APKs or whatever. It's been a while since I did it last... [online instructions if I forget]

But yeah any downloaded APK is a potential disaster for the person installing. The idea that a factory reset does NOT get rid of this particular malware is disturbing. Not sure how to EASILY do a complete re-flash though. It sounds like it would require more than an average tech... [maybe time to research doing that - I never went so far as to figure out how to do a complete re-flash on a 'droid device]

maybe future 'droid devices will need to ship with actual ROM (and not a potentially writable image) for a PROPER factory reset.

/me considers investigating how a debug USB cable might make this a little easier to deal with...

(I obviously STILL have a lot to learn about these things)

and yet - the absolute LAST thing we should want to see is an Apple-like (paywall and/or censor-wall) *STRANGLEHOLD* on what you can or cannot install... _ESPECIALLY_ for independent developers!

nice to see a breakdown of how it persists

Paul Shirley

Earlier reports seem to have not known how factory reset works and how little it actually does. If you're not into flashing 3rd party OS images I guess you just wouldn't think about recovery mode and reflashing - nuking the partitions from orbit.

Re: nice to see a breakdown of how it persists

bombastic bob

yes - it doesn't sound trivial at all. Maybe I should get another el-cheapo slab and try upgrading the old one, to improve my 'droid skills.

Here is a simple experiment that will teach you an important electrical
lesson: On a cool, dry day, scuff your feet along a carpet, then reach your
hand into a friend's mouth and touch one of his dental fillings. Did you
notice how your friend twitched violently and cried out in pain? This
teaches us that electricity can be a very powerful force, but we must never
use it to hurt others unless we need to learn an important electrical lesson.
It also teaches us how an electrical circuit works. When you scuffed
your feet, you picked up batches of "electrons", which are very small objects
that carpet manufacturers weave into carpets so they will attract dirt.
The electrons travel through your bloodstream and collect in your finger,
where they form a spark that leaps to your friend's filling, then travels
down to his feet and back into the carpet, thus completing the circuit.
Amazing Electronic Fact: If you scuffed your feet long enough without
touching anything, you would build up so many electrons that your finger
would explode! But this is nothing to worry about unless you have
carpeting.
-- Dave Barry, "What is Electricity?"