Rogue Android app texts humiliating messages
Real app's maker threatens to sue security firm for blogging about threat
Computerworld - Android users face a new threat, a rogue app that tells all their friends they pirated the program, a Symantec security manager said today.
The app is a fake copy of the legitimate "Walk and Text," software that uses the smartphone's camera to show what's in front of the user while she simultaneously walks and texts.
Walk and Text is available not only on Google's official Android Market app store, but also on numerous file-sharing sites. It's one of several mobile apps created by Georgi Tanmazov, the CEO of Incorporate Apps.
On the Android Market, Walk and Text is priced at $1.54.
The Trojanized version of the app includes malicious code that pilfers personal data from the phone -- the phone number, the device's unique identifier and more -- and sends it to a remote anonymous server.
That's not new, said John Engles, a group product manager with Symantec's security response team. What is new, at least on mobile devices, is the rogue app's texting of an embarrassing message to each contact in the phone's address book.
"Hey, just downlaoded [sic] a pirated App off the Internet," the message reads. "Walk and Text for Android. Im [sic] stupid and cheap, it costed [sic] only 1 buck. Don't steal like I did!"
When the app is run, a final message appears on the smartphone's screen that states, "We really hope you learned something from this." That message is accompanied by a an offer to buy the legitimate program from the Android Market.
According to Symantec, the rogue app -- which the company pegged as "Android.Walkinwat" and identified as a Trojan horse -- is similar to other fake Android apps that host malware. "They took the legitimate app, decompiled it, added the malicious code, recompiled it and then placed it on small Android side markets," said Engles.
Although Engles said the Trojan maker's motivation was unclear, he said it was most likely created by anti-piracy vigilantes. But it's also possible that the creator of Android.Walkinwat wanted to undermine the reputation of the legitimate Walk and Text application.
Engles called Android.Walkinwat "fairly benign," in part because it doesn't appear to have elements common to other mobile malware, such as a backdoor that allows secret downloads of other code.
"And it doesn't seem to be very popular or widespread," said Engles. Symantec has classified the rogue app/Trojan as a "Low" threat.
Installing the Trojanized app could result in higher texting bills, depending on the number of contacts in a victimized smartphone, and where those contacts lived. "This could cost you some money," said Engles.
- Google I/O 2013's Coolest Products and Services
- 10 Star Trek Technologies That are Almost Here
- 19 Generations of Computer Programmers
- 25 Must-Have Technologies for SMBs
- A walking tour: 33 questions to ask about your company's security
- 15 social media scams
- The 7 elements of a successful security awareness program
- IT Certification Study Tips
- Register for this Computerworld Insider Study Tip guide and gain access to hundreds of premium content articles, cheat sheets, product reviews and more.
- The Five Big Lies the C-Suite Hears About "Going Mobile" Mobile has already made a tremendous impact-to the tune of 29 billion apps downloaded in 2011. With such a new technology, it's not...
- mPayment Scenario Planning and Recommendations The mPayment industry is predicted to reach $1.3 trillion by 2017. This report offers conclusions into the impact mobile will have on businesses...
- New Report: Mobile Shopping Satisfaction Survey Many smartphone and tablet users say they might not shop at a retailer after a poor mobile-shopping experience. Take a look at this...
- Is Your App Getting Used? Understanding UX and Your Audience Want your app to be one of the 70 percent that is opened but never used again? If not, then you need to...
- 3 Reasons Why Sepaton is the World's Fastest Backup Solution Leading analyst, Storage Switzerland learns how Sepaton backs up and deduplicates massive data volumes while maintaining the industry's fastest performance - all in...
- Enterprise File Sharing: All You Need to Know Security. Scalability. Control. These are just some of the many benefits of enterprise cloud file-sharing that you'll discover in this KnowledgeVault, packed with... All Mobile Apps White Papers | Webcasts
Our weekly newsletter will cover a wide range of topics and trends related to consumerization. Stay up to date with news, reviews and in-depth coverage of BYOD, smartphones, tablets, MDM, cloud, social and how consumerization affects IT. Subscribe now!