Another supply-chain attack? Android maker Gigaset injects malware into victims' phones via poisoned update
- Reference: 1617826273
- News link: https://www.theregister.co.uk/2021/04/07/gigaset_supply_chain_malware_android_phones/
- Source link:
The Trojan, once downloaded and installed on a victim's device via a poisoned software update from the vendor, is capable of opening browser windows, fetching more malicious apps, and sending people text messages to further spread the malware, say researchers and users.
[1]
The malicious updates were seeded on April 1, judging by [2]reports out of Germany.
Our pals at [3]Heise also reported the wave of infections, whose perpetrators had not been identified at the time of writing. Heise observed this morning: "Permanent removal usually fails," meaning it's difficult to remove the persistent software nasty, adding that Gigaset's "quality assurance department" had confirmed "that the company's update server has delivered the malware."
[4]
Gigaset told the news website the incident only affects "older devices," and that it would provide more details soon. Users who head over to firm's forums will find that they are, or were at time of writing, " [5]down for maintenance ".
IT now stands for Intermediate Targets: Tech providers pwned by snoops eyeing up customers – report [6]READ MORE
The Munich-based outfit was formerly known as Siemens Home and Office Communications Devices, [7]according to Malwarebytes . The antivirus biz identified two of the malware strains emanating from Gigaset as Android/Trojan.Downloader.Agent.WAGD and Android/Trojan.SMS.Agent.YHN4.
The attack vector is a system update application, identified as com.redstone.ota.ui. Malwarebytes' Nathan Collier speculated in a post that crooks had compromised Gigaset's update servers to distribute the Trojans, a scenario Heise's reporting – and this [8]Google support thread – tends to confirm.
A reasonably complicated uninstallation method that successfully wipes the malware is available at the above link (if you're unfamiliar with command-line work, it's probably not for you).
A post on Gigaset's German-language corporate blog published yesterday talked at length about how criminals, er, [9]compromised a hospital thanks to "a weak point in the hospital's IT security." Great timing.
And in a statement to El Reg today, just as we were about to run this story, Gigaset senior veep for communications Raphael Dörr told us:
During routine control analyses, we noticed that some older smartphones had problems with malware. This finding was also confirmed by inquiries from individual customers.
We take the issue very seriously and are working intensively on a short-term solution for the affected users. In doing so, we are working closely with IT forensic experts and the relevant authorities. We will inform the affected users as quickly as possible and provide information on how to resolve the problem.
We expect to be able to provide further information and a solution within 48 hours. It is also important to mention at this point that, according to current knowledge, the incident only affects older devices.
We currently assume that the devices GS110, GS185, GS190, GS195, GS195LS, GS280, GS290, GX290, GX290plus, GX290 PRO, GS3 and GS4 are not affected. This is all we can say for the time being – we are still investigating.
[10]
While waiting for more information, and if it's an option or necessary, the safest non-technical solution is simply to turn off a potentially infected device and remove the battery and SIM. ®
Get our [11]Tech Resources
[1] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2YG4rfdunJ1e8L0pcR862XgAAAME&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0
[2] https://www.borncity.com/blog/2021/04/05/malwareangriff-was-gigaset-android-gertebesitzer-jetzt-machen-sollten/
[3] https://www.heise.de/news/Gigaset-Malware-Befall-von-Android-Geraeten-des-Herstellers-gibt-Raetsel-auf-6006464.html
[4] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33YG4rfdunJ1e8L0pcR862XgAAAME&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[5] https://www.gigaset.com/de_de/cms/csp/de/wartungsarbeiten-forum.html
[6] https://www.theregister.com/2019/09/19/it_supply_chain_attack/
[7] https://blog.malwarebytes.com/android/2021/04/pre-installed-auto-installer-threat-found-on-android-mobile-devices-in-germany/
[8] https://support.google.com/googleplay/thread/104068125?hl=de&msgid=104565503
[9] https://blog.gigaset.com/der-fehler-in-der-matrix-das-sicherheitsrisiko-mitarbeiter/
[10] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YG4rfdunJ1e8L0pcR862XgAAAME&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[11] https://whitepapers.theregister.com/
Have they thought of a free brand new clensed phone for all affected customers?
Turn it off?
Then how are you supposed to know if/when it's safe to ever turn it back on again? Unless you've got a second device with which to access the internet (not a given) & can look up said device safety status, the customer is now the unfortunate owner of a brick.
I wish I could say something funny to take the sting out of the situation, but GFDI this is enough to make me wish company execs could be held personally, criminally, financially liable for stuff like this. =-\
I had a similar issue with a Doogee phone a few years ago, and a solution until I found a clean ROM to reflash was to install the Noroot firewall app and then block everything from access the internet other than known safe apps. This stopped the malware being able to dial home. And then I was able to disable a couple of the malware apps from running.
Not ideal but at least it allowed me to carry on using the phone for none sensitive use for a while until i could fix
"We take the issue very seriously"
That's all right then.