Ads Place

DeathRing is a Chinese Trojan that is pre-installed on a number of low cost smartphones which are most popular in Asian and African countries. An end user cannot uninstalled or delete the DeathRing malware as it comes pre-installed in the system directory of the handsets at an unknown point within the supply chain, making the threat even more severe. 

WHAT DOES IT DO?
On infected mobiles, DeathRing pretends to be a ringtone app but can be used to download other malware, communicating with its command and control via SMS or even the ancient WAP.
"DeathRing might use SMS content to phish victim’s personal information by fake text messages requesting the desired data. It may also use WAP, or browser, content to prompt victims to download further APKs — concerning given that the malware authors could be tricking people into downloading further malware that extends the adversary’s reach into the victim’s device and data" the security firm LookOut wrote in a blog post.
AFFECTED DEVICES,
According to the LookOut the following handsets are pre loaded with the malware. 
  • Counterfeit Samsung GS4/Note II
  • A variety of TECNO devices
  • Gionee Gpad G1
  • Gionee GN708W
  • Gionee GN800
  • Polytron Rocket S2350
  • Hi-Tech Amaze Tab
  • Karbonn TA-FONE A34/A37
  • Jiayu G4S – Galaxy S4 clones,
  • Haier H7
  • a i9502+ Samsung clone by an unspecified manufacturer
THIS IS NOT A FIRST TIME,
Earlier this year, the security researchers in the firm LookOut have detect another pre-loaded piece of malware called Mouabad. Very similarly to DeathRing, Mouabad is also pre-installed somewhere in the supply chain and affected predominantly Asian countries.
Ads Place

Post a Comment

 
Top