Spyeye Attacks The Android
- Author Cee Simpson
- Published March 2, 2012
- Word count 520
SpyEye is a widespread malicious toolkit for creating and managing botnets. It is designed primarily for stealing banking credentials and other confidential information from infected systems.
SpyEye is a major competitor of the infamous Zeus toolkit. Emanating from Russia, it started to appear for sale on Russian underground forums. Retailing at $500, it is has taken a chunk of the Zeus crimeware toolkit market. Symantec detects this threat as Trojan.Spyeye.The Zeus (also known as ZBot) crimeware toolkit has grown to be the most established crimeware toolkit in the underground economy. It generated a lot of interest in the mobile security community a couple of months ago when an Android version was discovered.
It was not long before a version of SpyEye targeting Android was also developed, and sure enough a malicious SpyEye Android app was discovered a recently.
The functionality of Zeus and SpyEye on Windows is quite similar, and new revisions (of both), with additional features, are being released on a regular basis.
Zeus for Android purports to be a version of Trusteer Rapport security software. This social engineering trick is used in an attempt to convince the user that the application they are installing is legitimate.
Ads by Google
SpyEye for Android, now detected by Sophos products as Andr/Spitmo-A, uses a slightly different but similar social engineering technique.
When the user of a PC infected by the Windows version of SpyEye visits a targeted banking website, and when the site is using mobile transaction authorization numbers, the SpyEye Trojan may inject HTML content which will instruct the user to download and install the Android program to be used for transaction authorization.
The SpyEye application package does not show up as an icon in the "All apps" menu, so the user will only be able to find the package when the "Manage Applications" is launched from the mobile device's settings.
The application uses the display name "System" so that it seems like a standard Android system application.When installed, Zeus for Android displayed a fake activation screen, and Spitmo is again very similar.
However, Spitmo uses different tactics to convince the user that it is a legitimate application.
It applies for the following Android permissions:android.provider.Telephony.SMS_RECEIVED
android.intent.action.NEW_OUTGOING_CALL
This allows the malware to intercept outgoing phone calls.
When a number is dialed, the call is intercepted before the connection is made and the dialed phone number is matched to a special number specified by the attacker in the alleged helper application installation instructions.
If the number matches, Spitmo displays a fake activation number, which is always 251340.Once installed, the functionality of Zeus and SpyEye are pretty much the same.
A broadcast receiver intercepts all received SMS text messages and sends them to a command and control server using an HTTP POST request. The submitted information includes the sender's number and the full content of the message.
The developers of major malicious toolkits are closely watching their competition and matching the latest features. Users need to keep antimalware definitions up to date to minimize the effect of these evolving threats.
Cee Simpson is a Security Systems Analyst with EZMobilePC.com.
Article source: https://articlebiz.comRate article
Article comments
There are no posted comments.
Related articles
- Proven Strategies for Earning Serious Money Through Digital Products in 2025.
- Unlocking Wealth in the World's Largest Marketplace: Why Amazon Remains the Ultimate Money-Making Machine in 2025.
- Tracing Roots in the Digital Age: How Modern Genealogy is Revolutionizing Family History Research.
- Unlocking Primal Vitality: How the Paleo Diet Can Transform Your Health and Energy in the Modern World.
- New Shipment From India! Nature’s Harmony Carved Doors + Free Shipping Black Friday Deal
- New Arrivals: Artisan-Crafted Heritage Revival Furniture Collection
- How to Realistically Earn $1,000 a Day Online: The Path That Thousands Have Already Walked.
- Carb Cycling for Weight Loss: The Science-Backed Strategy That Keeps Metabolism Revved and Fat Burning High.
- Why You Should Look After Your Pets: The Lifelong Rewards of Responsible Care for Cats and Dogs.
- Etsy in 2025: Navigating Trends, Growth, and Opportunities in the Handmade Marketplace.
- Unlocking Profits: How Anyone Can Make Money with ChatGPT in 2025.
- Cultivating Nature’s Bounty: The Comprehensive Guide to Organic Gardening Success.
- The Science, Myths, and Strategies for Healthy Longevity
- Build Strength, Endurance, and Longevity.
- Email Marketing: The Timeless Strategy Driving 40x ROI in 2025.
- The Keto Revolution: Unlocking Peak Health Through Low-Carb Mastery.
- Intermittent Fasting: The Complete Guide to Transforming Your Health, Energy, and Longevity.
- Making Money With Facebook Ads.
- Clickbank Affiliate Marketing: The Ultimate Guide to Earning Passive Income in 2025.
- The Eternal Bloom: A Philosophical and Practical Journey Through Pregnancy.
- Breaking Phone Addiction: Reclaim Your Life and Focus.
- Why Children Need Early Reading Skills: Unlocking Lifelong Success Through Foundational Literacy
- “The Rise of the Antihero: From Tony Soprano to Joker.”
- Early Black Friday Starts Now: New Carved Doors & Heritage Furniture Just Landed!
- Festive Elegance: Embroidered Caftans for a Stylish Thanksgiving Hostess
- Give Thanks in Style: Transform Your Home with Antique & Carved Doors This Thanksgiving
- Top Secrets Behind the Best Forex Robot Every Trader Should Know
- Vintage Furniture, Armoires, and Sideboards in Luxury Rentals: Curating Character and Charm
- Hospitality Design and Carved Doors: Crafting First Impressions Through Artistry
- Exercises to Help Plantar Fasciitis in the Foot