Loapi is a New Form of Currency-Mining Android Malware CENTRiC A1 Smartphone...

 
 
 
Loapi is a New Form of Currency-Mining Android Malware CENTRiC A1 Smartphone...

 
xda-developers
Dec 23, 2017 6:30 AM • by Adam Conway
Loapi is a New Form of Currency-Mining Android Malware

The rise of Bitcoin, Litecoin, Monero, and other blockchain tech has coincided with a rise in currency-mining malware, or malicious apps that use your devices' hardware to generate digital coinage. Now, a new Android malware discovered by Sophos and dubbed Loapi (with the virus name Trojan.AndroidOS.Loapi) has reared its head. It's the first Android malware of its kind, and it's being described as a "jack of all trades".

Loapi isn't on the Google Play Store, and there's no evidence it's ever infected apps on the Play Store. Rather, it's served through advertisements and fake cracked apps, and often masquerades as pornography content and antivirus software.

loapi android malware

Source: Kaspersky

Loapi, once installed, forcibly prompts for device administrator access. It also polls devices for root access, but it isn't clear why — it doesn't seem to take advantage of root privileges. It's likely functionality that'll come in a future update.

loapi android malware

The malware attempting to gain device administrator access. (Source: Kaspersky)

Next, the application does one of two things: It either hides the app shortcut from the app drawer, or poses as a legitimate application. An example of the latter behavior's in the screenshots below, but things are a whole lot worse than they seem on the surface. Once the malware gains administrator access, it connects to multiple servers hosted by the attackers and downloads modules, or parts of the application which execute malicious actions. These modules are in the form of .so files, which are the Linux version of .dll files. Unlike executable files, these files are libraries meaning that sections of them can be called at any time. Executables have a fixed starting point.

Functionality of the Loapi Android Malware

Self-preservation

First and foremost, Loapi self-preserves. It restricts users from accessing the device administrator menu by closing it whenever it's opened from the settings menu, and prevents users from uninstalling the infected host app. What's more, it prompts users to uninstall any applications on the device that might pose a threat to it, like security apps and malware scanners. If the user doesn't uninstall them, the prompt shows continually as a toast message.

loapi android malware

Source: Kaspersky

Advertisements and Monero Cryptocurrency Mining

Loapi runs a number of advertising schemes that generate revenue in the background. Security researchers have observed it:

  • Displaying video ads and banners
  • Opening specific URLs
  • Creating shortcuts on the device
  • Showing notifications
  • Opening pages on popular social networks, including Facebook, Instagram, VK
  • Downloading and installing other applications

It can also mine Monero, a kind of cryptocurrency. Why Monero? To put it simply, as more transactions of a given cryptocurrency (like Bitcoin) are processed, the blockchain, which keeps track of all of the existing coins, increases the difficulty, making it harder to generate new coins. Monero isn't particularly valuable, but the difficulty is low enough that weaker devices can generate them. Loapi rotates between as many as ten different accounts in one Monero mining pool.

SMS Accessibilities

Loapi has full control over SMS on infected devices, and it has the ability to text premium-rate numbers. Here's what it can do:

  • Send inbox SMS messages to attackers' server
  • Reply to incoming messages according to specified masks (masks are received from a remote server)
  • Send SMS messages with specified text to specified number (all information is received from a remote server)
  • Delete SMS messages from inbox and sent folder according to specified masks (masks are received from a remote server)
  • Execute requests to URL and run specified Javascript code in the page received as a response (legacy functionality that was later moved to a separate module)

Many of the features aren't currently in use, but could be in the future.

WAP Billing

Retailers that allow you to bill purchases to your phone plan use a service called WAP (Wireless Application Protocol). Participating websites let you purchase something without the need for a bank account, and stick the charge to your monthly phone bill.

This service has been abused by malware in the past to make payments to sites attackers control, and Loapi is no different. Security researchers at SecureList found a built-in web crawler built that searches for these services online, and at one point, it opened 28,000 unique URLs in a 24-hour period.

DDoS and Proxy for Attackers

Finally, Loapi can create a proxy for attackers, meaning infected devices can be used to perpetrate a DDoS attack.


Results of the Loapi Android Malware

Things went from bad to worse in SecureList's testing of Loapi. Not only did the infected applications place a huge strain on the devices that ran them, but they posed a safety hazard — the test devices' batteries bulged as a result of high internal heat.

loapi android malware

The resulting damage to a Nexus 5 after the Loapi ran for two days. (Source: Kaspersky)

Here's the takeaway: Be careful what you download, and only download applications from trusted sources like the Play Store. There's no better way to avoid malware like Loapi.


Source: SourceLinks Via: Pixel Spot




Android Advices
Nov 24, 2017 2:17 PM • by Teja Chedalla
CENTRiC A1 Smartphone Launched with 5.5″ Full HD Display & Quick Charge 3.0 Support

Earlier this year, the Indian smartphone brand CENTRiC had launched four new budget smartphones – CENTRiC L1, CENTRiC P1, CENTRiC P1 Plus and CENTRiC G1. All these devices are priced under Rs. 10,000 and came with 4G VoLTE support. Now, the company is all set to launch a new smartphone called Centric A1. It is priced at Rs. 10,999 and offers unibody metal design. The smartphone will be available in Metallic Earl Grey, White & Peach Gold, Gold & Peach Gold color options.

Unlike many other smartphones in the budget segment, the CENTRiC A1 packs uncompromised specifications. It sports a 5.5-inch In-cell display with Full HD (1920 x 1080 pixels) and includes Dragontrail Glass protection on the top. Under the hood, the CENTRiC A1 is powered by a 64-bit Qualcomm Snapdragon 430 (MSM8937) Octa-core processor coupled with Adreno 505 GPU. It includes 3GB of RAM and 32GB of internal storage that can be expanded additionally up to 256GB via a MicroSD card.

On the rear of the device is a 13MP camera with PDAF, 5P lens, and dual LED flash. There is an 8MP front-facing camera with LED flash and 90-degree Field-of-View for wider selfies. The device supports dual SIM dual standby using the hybrid SIM slot. It is backed by a 3,000mAh non-removable that is rated to give up to 15 hours of talk time and lasts up to 210 hours in standby mode. The CENTRiC A1 also supports Quick Charge 3.0 that can give 4 hours of talk time with just 10 minutes of charging.

The fingerprint sensor is placed on the rear of the device. Connectivity options include 4G VoLTE, Wi-Fi 802.11 b/g/n, Bluetooth 4.0, GPS, A-GPS, FM Radio, 3.5mm headphone jack, and USB Type-C port. It runs on Android 7.1.1 Nougat out of the box, and there is no information about the Android 8.0 Oreo update. It also includes a bunch of sensors including Gyroscope, E-Compass, G-Sensor, Light sensor, Proximity sensor, and Hall sensor.

The CENTRiC A1 measures 152 x 76 x 7.8 mm and weighs 160 grams. Beneath the display are the three capacitive navigation button for back, home, and multitasking (left to right). Let us know, would you be interested in using a smartphone from a relatively new brand. Share your opinion with us by commenting down below.




 
 

This email has been sent by Froze ONE (isnanmm0@gmail.com). It is the potion result of 'Tech: Topic watch' from the dashboard 'Personal Dashboard', tab 'Tech > Android'. Unsubscribe

 
 
 

Subscribe to receive free email updates:

0 Response to "Loapi is a New Form of Currency-Mining Android Malware CENTRiC A1 Smartphone..."

Post a Comment