Website Malware Targets only Android Devices, take steps to Protect Yourself

Share this article

Android MalwareUntil recently, the authors of malware used Android apps to infect Android devices. Starting in January of this year, Google started aggressively scanning apps in the Google Play Store. In addition, Google scanned new apps and upgrades for malware. While not perfect, Google’s efforts greatly reduced the number of malware infected apps in the Google Play Store. With one door closed, the authors of malware are testing a new approach to install malware apps through infected Web sites.

Lookout was the first to discover the NotCompitable malware app. According to their report, a hacked Web site would contain a hidden iFrame at the bottom of the page. When the Android browser loads the page, it will attempt to load the file in the hidden iFrame. Upon loading the file, the browser would transfer control to the app loader, which would display an application installation screen, with the header com.Security.Update. An unsuspecting user might install the app, and thus infect their Android device.

The NotCompatible malware appears to be just a test, but it portends future attacks using a similar approach. To protect your mobile device from this form of attack, you should take the following actions:

  1. You should disable installation of apps from “Unknown source.” You will find this option under Settings -> Applications. While this blocks the side-loading of applications, it also protects your Android device from installing applications using drive-by attacks, such as NotCompatible. You can always enable the option, when you do need it to install a side-loaded application.
  2. As a mentioned in the article “Protecting from Internet Malware on your Smartphone, Laptop, Tablet,” you should install an anti-virus app. These anti-virus apps are free, and provide excellent protection: avast! Mobile Security, NQ Mobile Security & Antivirus, and Lookout Mobile Security.
  3. Always check the permissions requested, before installing an app. When an app asks for permissions that go beyond the needs of the app, find another app that provides the same function. For example, the Flashlight app request permissions to access phone state and identity, change user interface settings, and to modify global parameters. These permissions go beyond the needs of a simple flashlight app. There is another app, with the same name. This Flashlight app only requests uses of the camera, so that it can turn on the LED.
  4. Many apps depend on advertising to support the developer. Reasonable ads are one thing, but many apps use your information to send unwanted advertising to your mobile device. While permissions give you clues, they do not provide details as to the ad networks used by the app. The AppBrain Ad Detector app analyzes apps to insure that the app does not disclose personal information to ad networks. It helps you get rid of ad notifications and ad bookmarks from your screen pages. AppBrain Ad Detector helps you detect permissions that give access to your messages, accounts, and allow invocation of services that can cost you money. When it scans your mobile device, AppBrain Ad Detector flags apps with a color code: green is safe, yellow means potentially a problem, and red means that you need to review the permissions for the app. Not all apps flagged as red are a problem. For example, an anti-virus app gets flagged as red due to the permissions required to support the app. You can set AppBrain Ad Detector to scan new apps and updates, before they are installed.

With over 600 million Android devices in the world, the purveyors of malware will always be seeking ways to infect your Android device. By following the above steps, you can protect your Android device from their malicious attempts.

Print Friendly, PDF & Email

Comments