A single family of malware accounts for most of the current infections on Android devices, according to a new study.
Mobile security firm Cheetah Mobile examined what it said are the two most prevalent Trojan horses on Android – called com.sms.sys.manager and com.al.alarm.controller – and found they were slightly altered variants of a single family, known as Ghost Push.
The two variants were discovered in January, but Ghost Push itself has been around for several years and has been updated a number of times, Cheetah said.
It’s capable of gaining root privileges on most Android devices running software up to and including version 5, known as Lollipop.
The two newer releases, Marshmallow and Nougat, aren’t vulnerable to Ghost Push, but Cheetah found most users are still running the older software.
Because it gains root privileges, the Trojan is able to install itself in such a way that it’s difficult to remove, Cheetah said. It promotes and automatically installs further apps and displays adverts to generate funds.
Based on data from Cheetah’s security products, the study estimated malware accounts for at least one percent of all applications installed on Android each day.
“The actual amount of malware is far more than this,” the firm said.
Most of the malicious programs are spread through porn websites, deceptive short-links and malicious ads.
Users can protect themselves by avoiding unknown third-party links and downloading software only from reputable app stores, such as those of Google or Amazon.
The figures demonstrate the security risk posed by Android’s decentralised model, which means most users don’t have access to regular operating system updates, according to computer security researcher Graham Cluley.
Handsets manufactured by Google have direct access to updates, but those from other companies may not, he said.
“Carriers, smartphone manufacturers and Google all have to work in unison to get an update pushed out to users,” he said. “And they just don’t seem to have enough incentive to pull together in the right direction.”
Are you a security pro? Try our quiz!
Fourth quarter results beat Wall Street expectations, as overall sales rise 6 percent, but EU…
Hate speech non-profit that defeated Elon Musk's lawsuit, warns X's Community Notes is failing to…
Good luck. Russia demands Google pay a fine worth more than the world's total GDP,…
Google Cloud signs up Spotify, Paramount Global as early customers of its first ARM-based cloud…
Facebook parent Meta warns of 'significant acceleration' in expenditures on AI infrastructure as revenue, profits…
Microsoft says Azure cloud revenues up 33 percent for September quarter as capital expenditures surge…