Menu
Symantec spots two Android apps using 'master key' vulnerability

Symantec spots two Android apps using 'master key' vulnerability

The applications help Chinese users schedule medical appointments

Hackers are now using a critical vulnerability in Android to modify legitimate smartphone applications, putting users at risk of being spied on.

Security vendor Symantec wrote on Tuesday that it found two applications being distributed in Chinese Android marketplaces that have employed the "master key" vulnerabilities discovered earlier this month.

Both applications, used to find and schedule medical appointments, are legitimate but have been modified by hackers, Symantec wrote on its blog.

Inserted into the programs is code that lets an attacker remotely control an Android device and collect data such as phone numbers and the device's IMEI number. It can also deactivate some Chinese mobile security software programs.

Additionally, the code can command a device to send SMSes to a premium number, a scam where an attacker controls the number and collects the fees charged to the victim.

One of the master key vulnerabilities was uncovered by a mobile security vendor, Bluebox Security. The company found that an Android package file, used to install an application, could be modified in a way that did not affect the application's original cryptographic digital signature. The signature verifies an application's integrity. A second, similar vulnerability was published on a Chinese forum.

Google quickly issued patches for the problems, which may affect as many as 900 million devices made over the last four years running Android versions 1.6 and higher.

Mobile phone operators must either send a patch out to users, which can be a slow process, or users must apply a patch themselves, which is unlikely for less-sophisticated smartphone users. Some security vendors have issued their own software to fix the vulnerability.

Google is scanning applications in its Play store to weed out programs that might be infected. Symantec also gave the usual security advice for users to only download applications from reputable Android marketplaces.

"We expect attackers to continue to leverage this vulnerability to infect unsuspecting user devices," the company wrote.

Send news tips and comments to jeremy_kirk@idg.com. Follow me on Twitter: @jeremy_kirk


Follow Us

Join the newsletter!

Or

Sign up to gain exclusive access to email subscriptions, event invitations, competitions, giveaways, and much more.

Membership is free, and your security and privacy remain protected. View our privacy policy before signing up.

Error: Please check your email address.

Tags securitymobilesymantecMobile OSesExploits / vulnerabilities

Featured

Slideshows

Meet the leading female front runners of the Kiwi channel

Meet the leading female front runners of the Kiwi channel

Reseller News honoured the leading female front runners of the New Zealand channel at the 2018 Women in ICT Awards (WIICTA) in Auckland. The awards honoured standout individuals across seven categories, spanning Entrepreneur; Innovation; Rising Star; Shining Star; Community; Technical and Achievement.

Meet the leading female front runners of the Kiwi channel
Meet the top performing customer-centric Microsoft channel partners

Meet the top performing customer-centric Microsoft channel partners

Microsoft honoured leading partners across the channel following a year of customer innovation and market growth in New Zealand. The 2018 Microsoft Partner Awards recognised excellence within the context of the end-user, spanning a host of emerging and established providers.

Meet the top performing customer-centric Microsoft channel partners
Reseller News launches new-look Awards at 2018 Judges’ Lunch

Reseller News launches new-look Awards at 2018 Judges’ Lunch

Introducing the Reseller News Innovation Awards, launched to the channel at the 2018 Judges’ Lunch in Auckland. With more than 70 judges now part of the voting panel, the new-look awards will reflect the changing dynamics of the channel, recognising excellence across customer value and innovation - spanning start-ups, partners, distributors and vendors.

Reseller News launches new-look Awards at 2018 Judges’ Lunch
Show Comments