Crooks Use Google’s Own Cloud To Control Android Malware

Cyber criminals are controlling Android malware using Google’s own cloud, helping them update bad apps to add fresh functionality without being blocked.

A host of typical Android malware is being updated via Google Cloud Messaging, a service that lets developers send data, such as advertising information, small messages and commands, to users of their applications.

As GCM is an official Google service, it is  impossible to block updates directly on an infected device, Kaspersky Lab warned. Developers have to get a unique ID from Google to use GCM, indicating Google is unwittingly granting them to cyber crooks.

Abusing Google to control Android malware

The criminals use GCM to initiate updates, advertise other malicious programs or have infected devices send text messages. Effectively, the Google cloud is exploited to become part of the attackers’ command and control infrastructure.

Fakelnst.a Trojan, one of the most prevalent Android threats that sends text messages to premium numbers and can delete incoming text messages, is registered with GCM. That particular malware is prevalent in Russia, and Kaspersky said it had detected over 4.8 million Fakelnst.a installers to date.

The Agent.ao malware, which is prevalent in the UK, used GCM to retrieve updates and create notifications with information or advertising content.

Many of the bad applications are pornography sites, and none are on the official Google Play market. Users are advised to only download apps from trusted sources.

“The execution of commands received from GCM is performed by the GCM system and it is impossible to block them directly on an infected device,” said Kaspersky Lab expert Roman Unuchek, in a blog post.

“The only way to cut this channel off from virus writers is to block developer accounts with IDs linked to the registration of malicious programs.”

What do you know about Internet security? Find out with our quiz!

Thomas Brewster

Tom Brewster is TechWeek Europe's Security Correspondent. He has also been named BT Information Security Journalist of the Year in 2012 and 2013.

Recent Posts

Northvolt Files For Bankruptcy Protection In US

Northvolt files for Chapter 11 bankruptcy protection in the United States, and CEO and co-founder…

2 hours ago

UK’s CMA Readies Cloud Sector “Behavioural” Remedies – Report

Targetting AWS, Microsoft? British competition regulator soon to announce “behavioural” remedies for cloud sector

17 hours ago

Former Policy Boss At X Nick Pickles, Joins Sam Altman Venture

Move to Elon Musk rival. Former senior executive at X joins Sam Altman's venture formerly…

19 hours ago

Bitcoin Rises Above $96,000 Amid Trump Optimism

Bitcoin price rises towards $100,000, amid investor optimism of friendlier US regulatory landscape under Donald…

21 hours ago

FTX Co-Founder Gary Wang Spared Prison

Judge Kaplan praises former FTX CTO Gary Wang for his co-operation against Sam Bankman-Fried during…

21 hours ago