Underground Android Tool To Target PC Data

Underground malware pushers have created an Android app that can be used to steal data from PCs, whose highly-targeted nature has surprised researchers.

The tool was discovered on a Chinese language hacker forum and affects Android and Windows users. It  installs an app named USBCleaver, which, upon launch, directs victims to download a ZIP file from a remote server.

Android the target

Additional files are saved on to the user’s system, which direct the Android device to extract data from a Windows machine when connected via USB. That data includes browser passwords, affecting the three most popular browsers: Firefox, Chrome and Internet Explorer.

The PCs Wi-Fi password and the PC’s network information are also siphoned off, F-Secure said. The company noted the malware’s uniqueness lay in its targeted nature.

“USBCleaver seems to be designed to facilitate a targeted attack by gathering details that would be helpful in a later infiltration attempt,” F-Secure said in a blog post.

“To run the utilities, the sample creates an autorun.inf and go.bat file at /mnt/sdcard. When the device is connected to a Windows computer, the autorun script gets triggered, which then silently runs the go.bat file in the background, which in turn runs the specified files from the usbcleaver/system folder.

“The collected details are stored on the device at /mnt/sdcard/usbcleaver/logs.The app’s user can click on the ‘Log Files’ button to view the information retrieved from the PC.”

F-Secure advised users to disable autorun by default, as this should prevent the threat working.

Android malware continues to be the scourge of the mobile world. Juniper Networks recently claimed Android was the target for 92 percent of all known mobile malware.

Think you know everything about Android? Try our quiz!

Thomas Brewster

Tom Brewster is TechWeek Europe's Security Correspondent. He has also been named BT Information Security Journalist of the Year in 2012 and 2013.

Recent Posts

Apple, Google Mobile Ecosystems Should Be Investigated, CMA Told

CMA receives 'provisional recommendation' from independent inquiry that Apple,Google mobile ecosystem needs investigation

2 days ago

Australia Rejects Elon Musk Claim About Social Media Ban For Under-16s

Government minister flatly rejects Elon Musk's “unsurprising” allegation that Australian government seeks control of Internet…

2 days ago

Northvolt Files For Bankruptcy Protection In US

Northvolt files for Chapter 11 bankruptcy protection in the United States, and CEO and co-founder…

2 days ago

UK’s CMA Readies Cloud Sector “Behavioural” Remedies – Report

Targetting AWS, Microsoft? British competition regulator soon to announce “behavioural” remedies for cloud sector

3 days ago

Former Policy Boss At X, Nick Pickles, Joins Sam Altman Venture

Move to Elon Musk rival. Former senior executive at X joins Sam Altman's venture formerly…

3 days ago

Bitcoin Rises Above $96,000 Amid Trump Optimism

Bitcoin price rises towards $100,000, amid investor optimism of friendlier US regulatory landscape under Donald…

3 days ago