• English
  • Deutsch
  • Log In
    Password Login
    Research Outputs
    Fundings & Projects
    Researchers
    Institutes
    Statistics
Repository logo
Fraunhofer-Gesellschaft
  1. Home
  2. Fraunhofer-Gesellschaft
  3. Buch
  4. An investigation of the Android/BadAccents malware which exploits a new Android tapjacking attack
 
  • Details
  • Full
Options
2015
Report
Title

An investigation of the Android/BadAccents malware which exploits a new Android tapjacking attack

Abstract
We report on a new threat campaign, underway in Korea, which infected around 20,000 Android users within two months. The campaign attacked mobile users with malicious applications spread via different channels, such as email attachments or SMS spam. A detailed investigation of the Android malware resulted in the identification of a new Android malware family Android/BadAccents. The family represents current state-of-the-art in mobile malware development for banking trojans. In this paper, we describe in detail the techniques this malware family uses and confront them with current state-of-the-art static and dynamic code-analysis techniques for Android applications. We highlight various challenges for automatic malware analysis frameworks that significantly hinder the fully automatic detection of malicious components in the malware. Furthermore, the malware exploits a previously unknown tapjacking vulnerability in the Android operating system, which we describe in detail. As a result of this work, the vulnerability, affecting all Android versions, has been patched in the Android Open Source Project.
Author(s)
Rasthofer, Siegfried
Asrar, Irfan
Huber, Stephan
Bodden, Eric  
Publisher
Fraunhofer SIT
Publishing Place
Darmstadt
Link
Link
Language
English
Fraunhofer-Institut für Sichere Informationstechnologie SIT  
Keyword(s)
  • Botnet

  • threat campaign

  • Android Malware

  • code analysis

  • banking trojans

  • vulnerability

  • Cookie settings
  • Imprint
  • Privacy policy
  • Api
  • Contact
© 2024