Get the latest Updates on all things Tech

Tech Cravings will provide you with the latest and greatest tech tips and trick as well as the latest Tech Updates

Get connected

Connect with many other people with the same interests as you as you explore Tech cravings.

Follow the latest news on All things Apple, Google and Microsoft

FInd the latest news on Technology Cravings! If its anything related to tech , count on us to keep you up to date

Showing posts with label Security fix. Show all posts
Showing posts with label Security fix. Show all posts

Thursday, 15 September 2016

DualToy Windows Trojan Attacks Android, iOS Devices

 

A Windows Trojan called DualToy has been discovered that can side load malicious apps onto Android and iOS devices via a USB connection from an infected computer. Researchers from Palo Alto Networks said DualToy has been in existence since January 2015, and it originally was limited to installing unwanted apps and displaying mobile ads on Android devices. About six months later, the Trojan morphed and began targeting iOS devices by installing a third-party App Store in hopes of nabbing iTunes usernames and passwords.

See more at: DualToy Windows Trojan Attacks Android, iOS Devices https://wp.me/p3AjUX-vms
A Windows Trojan has been discovered that can sideload malicious apps onto your iOS or android running devices. The Trojan is transferred to your phone when you connect it to the infected computer via a USB cable

Researchers say that this Trojan has been around for quite some time, Specifically from January of 2015, However it was initially only limited to installing unwanted apps and displaying mobile ads on Android devices. 6 months later the Trojan changed and began targeting iOS devices by installing a third party app store in hopes of gaining access to iTunes usernames and passwords.

Researchers say that once Dual Toy, The Trojan, infects a windows machine, it looks for the Android debug bridge (ADB) and iTunes . and downloads drivers for both if they're missing in order to infect mobile devices once connected. According to the team of researchers, they have encountered approximately over 8,000 unique samples of the Dual Toy variant to date and are still not sure how many mobile devices were affected because of this malicious bug.

During the past two years there have been similar cases of windows and iOS malware designed to attack mobile devices via side loading techniques.So far the Trojan only affects Chinese users but researchers say that users from the United States, United Kingdom,Thailand,Spain and Ireland have also been affected.

Its still unclear as to how the Dual Toy Trojan actually infects a Windows machine. But once its on a windows PC it downloads from a command and control server file called adb.exe , which is standard Android Debug Bridge on Windows clients. However more recent variants of Dual Toy drop a custom ADB client called tadb.exe, onto the victim's PC. The malware also downloads two installers, "AppleMobileDevicesSupport64.msi" and "AppleApplicationSupport64.msi" , which is part of Apple's official iTunes for windows software.

On Android devices , Dual Toy installs several Chinese language apps that researchers suspect attackers are getting paid per install by the game developers. On iOS devices the Trojan installs a fake iOS app store , trying to trick users into giving their iTunes email and password.

The use of a fake iOS app store is not unique. There are several other examples of a malware like Dual Toy including ZergHelper and AceDeciever. What these do is , as soon as the user opens the fake app, they are prompted to provide the app with their iTunes i.d and password and not knowing that this is a scam, they willingly give the attackers their account.

 
A Windows Trojan called DualToy has been discovered that can side load malicious apps onto Android and iOS devices via a USB connection from an infected computer. Researchers from Palo Alto Networks said DualToy has been in existence since January 2015, and it originally was limited to installing unwanted apps and displaying mobile ads on Android devices. About six months later, the Trojan morphed and began targeting iOS devices by installing a third-party App Store in hopes of nabbing iTunes usernames and passwords.

See more at: DualToy Windows Trojan Attacks Android, iOS Devices https://wp.me/p3AjUX-vms
A Windows Trojan called DualToy has been discovered that can side load malicious apps onto Android and iOS devices via a USB connection from an infected computer. Researchers from Palo Alto Networks said DualToy has been in existence since January 2015, and it originally was limited to installing unwanted apps and displaying mobile ads on Android devices. About six months later, the Trojan morphed and began targeting iOS devices by installing a third-party App Store in hopes of nabbing iTunes usernames and passwords.

See more at: DualToy Windows Trojan Attacks Android, iOS Devices https://wp.me/p3AjUX-vms
A Windows Trojan called DualToy has been discovered that can side load malicious apps onto Android and iOS devices via a USB connection from an infected computer. Researchers from Palo Alto Networks said DualToy has been in existence since January 2015, and it originally was limited to installing unwanted apps and displaying mobile ads on Android devices. About six months later, the Trojan morphed and began targeting iOS devices by installing a third-party App Store in hopes of nabbing iTunes usernames and passwords.

See more at: DualToy Windows Trojan Attacks Android, iOS Devices https://wp.me/p3AjUX-vms
Share:

Google patches two major Android security bugs - but are you still at risk?


As you all may or may not have known, Google has been working hard at patching some potentially serious Android mobile security flaws.

The company has thus fixed two major security issues that could have left millions of devices at risk of being hijacked by criminals.The flaw that i mentioned includes a variant of of the stagefright bug (which was uncovered last year and affected nearly a billion Android devices across the world). This flaw however is not the same as stagefright but but behaves similarly to it. This virus would allow hijackers to hack your device using a specially created j-peg image file , sent through Gmail and other Google services. This would allow the attackers to gain control of the device and have access to personal information or would also let them shut it down completely.

Users, who don't even download the image will be hit by the malicious bug . This means that anyone who even views the bug ( The J-peg image file) would be affected the by it. 


The other bug was similar to this bug. By the same process (the J-peg image file) hackers would gain control of the device and this would allow them to execute malware or gain access to personal information or programs on affected devices by escalated local privileges.

Know as CVE 2016-3861, Google says that it was designed only for research purposes but if in the wrong hands , could be used for some serious damage. The updates are included in Google's latest security patches ,which are available to nexus device users now , and will be rolling out to other devices very soon. However even users who have installed the update could find themselves being attacked by criminals. It seems that the Google Play store hosted apps that contain two nasty forms of malware. 

The offending apps have now been removed by google , but there's no word on how many times the apps were downloaded , meaning millions of android users could be at risk of being affected by the bug. 

Make sure that you only download the essential apps and report any app that seems fishy on the Playstore.
Share:
Techcravings. Powered by Blogger.

Blog Archive