Android adware wields potent root exploits to gain permanent foothold

Source 
Author 
Coverage Type 

Researchers have uncovered yet another Android-based adware campaign targeting people who download what they believe are trusted titles from websites and other third-party app stores. The apps use repackaged icons to disguise themselves as popular titles and are offered for download through pop-up ads on visited websites and in-app promotions, according to researchers from security firm FireEye.

Once installed, the apps exploit as many as eight separate Android vulnerabilities that allow the apps to gain deep root access privileges. From there, the apps launch code libraries mimicking legitimate Android services to gain a permanent foothold on infected phones. The FireEye blog post is another reminder of the threats that come from Android apps available in third-party app stores. No doubt, Google's security vetting of apps is by no means perfect, but it does offer a level of protection that's generally not available elsewhere. Android users should make use of it whenever possible and remain highly suspicious of other sources.


Android adware wields potent root exploits to gain permanent foothold