时间:2025-11-22 11:06:16 来源:网络整理编辑:焦點
A new strain of Android malware has infected 25 million devices and modified legitimate apps with a
A new strain of Android malware has infected 25 million devices and modified legitimate apps with a malicious ads module, according to a report by the security company Check Point.
It's believed the malware originated from a Chinese internet company that helps Chinese Android developers publish and promote their apps in foreign markets. The malware was disguised as Google-related updaters and "vending modules," which hid its own app icons and automatically replaced already-installed legitimate apps with its own version without the user knowing. This lead the researchers to name the malware "Agent Smith" because its behavior is similar to the character in the film The Matrixof the same name.
The malware first appeared in popular third-party app store 9Apps and targeted mostly Indian, Pakistani and Bangladeshi users. However, of the 25 million affected devices, 303,000 infections were detected in the US, and 137,000 in the UK.
Apps that were modified include WhatsApp, Opera Mini, Flipkart, as well as software from Lenovo and Swiftkey. The malware detected which apps were installed, patched them with a malicious ads modules, and then re-installed them on the device. For the user, it simply looks like the app is being updated as expected. Once the update is complete, the owner of the malware can then profit from the newly included ads.
Check Point believes the same malware could also be used for more malicious purposes such as credit card theft, with the company's report stating, "due to [the malware's] ability to hide its icon from the launcher and impersonates any popular existing apps on a device, there are endless possibilities for this sort of malware to harm a user's device."
The security firm says they submitted data to Google and law enforcement agencies, and as of publishing no malicious apps remain on the Play Store. Nevertheless, the malware managed to survive for as long as it did because, despite the original vulnerability Agent Smith was based on being patched in Android years ago, developers did not sufficiently update their applications.
Malware like this, "requires attention and action from system developers, device manufacturers, app developers, and users, so that vulnerability fixes are patched, distributed, adopted and installed in time," Check Point says.
TopicsAndroidCybersecurity
Felix the cat just raised £5000 for charity because she's the hero we all need2025-11-22 11:05
國足戰阿曼決定兩隊最終走向 12月中超大概率推遲2025-11-22 10:27
深度:曼聯的壓迫非結構性 完爆C羅用不著薩拉赫2025-11-22 09:41
大連人主帥:會派更多年輕人出場 希望球員展現出個性2025-11-22 09:25
We asked linguists if Donald Trump speaks like that on purpose2025-11-22 09:19
拜仁VS門興首發:萊萬穆勒薩內領銜 磁卡阿芳回歸2025-11-22 09:12
黎巴嫩男足12強賽表現出色 黎足協重獎5千美元2025-11-22 09:09
裏皮前助教馬達洛尼再就業 擔任意丙俱樂部主教練2025-11-22 08:52
Tributes flow after death of former Singapore president S.R. Nathan2025-11-22 08:43
河南代理主帥:有自信和能力解決問題 目標就是取勝2025-11-22 08:28
Tributes flow after death of former Singapore president S.R. Nathan2025-11-22 11:05
黎巴嫩男足12強賽表現出色 黎足協重獎5千美元2025-11-22 10:59
官方:女足亞洲杯抽簽儀式28日15點舉行 中國在第二檔2025-11-22 10:24
四川隊或仍全華班出戰河南 李毅:抱著學習的態度踢2025-11-22 10:22
This weird squid looks like it has googly eyes, guys2025-11-22 09:33
兩大聯賽杯殺手助紅軍晉級 三線出擊仍保持不敗2025-11-22 09:30
西班牙人前瞻:表現平淡+缺乏信任 武磊難獲首發2025-11-22 09:16
萊科:奧斯卡賀慣出場仍存疑 不會因為首回合取勝放鬆2025-11-22 09:13
Make money or go to Stanford? Katie Ledecky is left with an unfair choice.2025-11-22 09:05
比賽日:比利亞雷亞爾32025-11-22 08:56