Menu
Symantec spots two Android apps using 'master key' vulnerability

Symantec spots two Android apps using 'master key' vulnerability

The applications help Chinese users schedule medical appointments

Hackers are now using a critical vulnerability in Android to modify legitimate smartphone applications, putting users at risk of being spied on.

Security vendor Symantec wrote on Tuesday that it found two applications being distributed in Chinese Android marketplaces that have employed the "master key" vulnerabilities discovered earlier this month.

Both applications, used to find and schedule medical appointments, are legitimate but have been modified by hackers, Symantec wrote on its blog.

Inserted into the programs is code that lets an attacker remotely control an Android device and collect data such as phone numbers and the device's IMEI number. It can also deactivate some Chinese mobile security software programs.

Additionally, the code can command a device to send SMSes to a premium number, a scam where an attacker controls the number and collects the fees charged to the victim.

One of the master key vulnerabilities was uncovered by a mobile security vendor, Bluebox Security. The company found that an Android package file, used to install an application, could be modified in a way that did not affect the application's original cryptographic digital signature. The signature verifies an application's integrity. A second, similar vulnerability was published on a Chinese forum.

Google quickly issued patches for the problems, which may affect as many as 900 million devices made over the last four years running Android versions 1.6 and higher.

Mobile phone operators must either send a patch out to users, which can be a slow process, or users must apply a patch themselves, which is unlikely for less-sophisticated smartphone users. Some security vendors have issued their own software to fix the vulnerability.

Google is scanning applications in its Play store to weed out programs that might be infected. Symantec also gave the usual security advice for users to only download applications from reputable Android marketplaces.

"We expect attackers to continue to leverage this vulnerability to infect unsuspecting user devices," the company wrote.

Send news tips and comments to jeremy_kirk@idg.com. Follow me on Twitter: @jeremy_kirk


Follow Us

Join the newsletter!

Or

Sign up to gain exclusive access to email subscriptions, event invitations, competitions, giveaways, and much more.

Membership is free, and your security and privacy remain protected. View our privacy policy before signing up.

Error: Please check your email address.

Tags mobilesymantecMobile OSesExploits / vulnerabilities

Events

Featured

Slideshows

Meet the Reseller News 30 Under 30 Tech Awards 2020 winners

Meet the Reseller News 30 Under 30 Tech Awards 2020 winners

This year’s Reseller News 30 Under 30 Tech Awards were held as an integral part of the first entirely virtual Emerging Leaders​ forum, an annual event dedicated to identifying, educating and showcasing the New Zealand technology market’s rising stars. The 30 Under 30 Tech Awards 2020 recognised the outstanding achievements and business excellence of 30 talented individuals​, across both young leaders and those just starting out. In this slideshow, Reseller News honours this year's winners and captures their thoughts about how their ideas of leadership have changed over time.​

Meet the Reseller News 30 Under 30 Tech Awards 2020 winners
Reseller News Exchange Auckland: Beyond the myths — how partners can master cloud security

Reseller News Exchange Auckland: Beyond the myths — how partners can master cloud security

This exclusive Reseller News Exchange event in Auckland explored the challenges facing the partner community on the cloud security frontier, as well as market trends, customer priorities and how the channel can capitalise on the opportunities available. In association with Arrow, Bitdefender, Exclusive Networks, Fortinet and Palo Alto Networks. Photos by Gino Demeer.

Reseller News Exchange Auckland: Beyond the myths — how partners can master cloud security
Reseller News welcomes industry figures at 2020 Hall of Fame lunch

Reseller News welcomes industry figures at 2020 Hall of Fame lunch

Reseller News welcomed 2019 inductees - Leanne Buer, Ross Jenkins and Terry Dunn - to the fourth running of the Reseller News Hall of Fame lunch, held at the French Cafe in Auckland. The inductees discussed the changing face of the IT channel ecosystem in New Zealand and what it means to be a Reseller News Hall of Fame inductee. Photos by Gino Demeer.

Reseller News welcomes industry figures at 2020 Hall of Fame lunch
Show Comments