Android malware explodes, jumps five-fold since July
'Exponential growth' driven by Google's policy of not vetting apps, veteran hackers moving to Android
Computerworld - Malware targeting Google's Android mobile operating system exploded in the last several months, its volume quintupling since July, Juniper Networks said today.
The rash of infected apps aimed at Android owners shows no sign of abating, said Dan Hoffman, Juniper's chief mobile security analyst and a member of the company's global threat center.
"We're seeing a mix of the traditional hacking community [working] on malware very similar to organized efforts on the PC side, as well as people who are just a little smart, the '15-year-old kid crowd,' who are able to hide some malicious content in an app," said Hoffman in an interview today.
According to Juniper's research, the number of Android malware samples -- each defining a different piece of attack code, or a variant of one discovered earlier -- increased by 472% since July 2011. The bulk of that growth occurred in September and October.
"We've seen an exponential growth in Android malware over the last several months," Juniper said in a blog post that accompanied Juniper's recently-published mobile threat report.
The prime threat remains purposefully-malicious Android apps that are crafted by criminals, often pirated versions of legitimate applications, then planted in either Google's official Android Market or in one of the scores of alternate download sites, which are especially popular in Asia -- China in particular.
"That is very clearly the threat now," said Hoffman, who added that the hackers' strategy would likely continue indefinitely.
That's because Google doesn't control what apps can be installed on an Android mobile device, as Apple does with code-signing technologies for iOS apps, and so makes third-party app download centers possible. Nor does Google vet apps submitted to the Android Market.
Other security researchers have noted the same when they have found malicious apps in the Android Market or in unsanctioned e-stores.
At least three different waves of malware -- in March, June and finally July -- infiltrated the Android Market this year. The malicious apps were removed by Google only after they had been downloaded by an unknown number of users.
Far more attack apps have appeared in Chinese app stores that distribute Android software.
Juniper speculated that the hackers now crafting Android malware are those who used to specialize in Symbian and Windows Mobile attack code. But as those operating systems' share plummeted -- Web metrics company Net Applications put their shares during October at 3.5% and 0.07%, respectively, down from 8% and 0.2% a year ago -- the criminals have abandoned those platforms and jumped on Android.
And those hackers know their stuff.
Google's Android OS
- Optimus G Pro deep-dive review: A supersized smartphone done right
- AT&T to carry LG Optimus G Pro for $200 and contract May 10
- Samsung Galaxy S4 deep-dive review: A real-world evaluation
- HTC One deep-dive review: A smartphone that flirts with perfection
- Despite Schmidt comments, merger of Chrome OS, Android still possible, analyst says
- Samsung offers barely a mention of Android amid Galaxy S4 hoopla
- Samsung unveils Galaxy S4 with novel camera design
- Kanye West helps launch Samsung's Galaxy Note II
- First look: HTC One X+ shines
- Google's Motorola unit drops one trade case against Apple
- The 20 Best iPhone/iPad Games of 2013 So Far
- 9 Steps to Build Your Personal Brand (and Your Career)
- 7 Consumer Technologies Coming to an Enterprise Near You
- 11 Signs Your IT Project is Doomed
- A walking tour: 33 questions to ask about your company's security
- 15 social media scams
- The 7 elements of a successful security awareness program
- IT Certification Study Tips
- Register for this Computerworld Insider Study Tip guide and gain access to hundreds of premium content articles, cheat sheets, product reviews and more.
-
Your Data under Siege: Protection in the Age of BYODs
Download Kaspersky Lab's new whitepaper, Your Data under Siege: Protection in the Age of BYODs, to learn about:
- How a mobile workforce stretches... - Protection for Every Enterprise: How BlackBerry 10 Security Works Get an IT-level review of BlackBerry® 10 Security, addressing data leakage protection, certified encryption, containerization and much more.
- A Comprehensive Strategy to Leverage Mobile A successful mobile strategy begins with a common platform for integrating and managing mobile devices and the corporate assets that are stored on...
- IDC - SAP Enterprise Mobility: Bringing a Cohesive Approach to a Complex Market This IDC white paper discusses key mobility trends and examines how SAP's mobile enterprise solutions map to meet organization's mobile requirements.
- Boost Performance & Profitability with Better Planning & Mobile Reporting This session will discuss how Ashurst, a top-tier legal service provider for private and public sector clients worldwide, was able to effectively manage...
- Apps and BlackBerry 10 - Tips for IT Learn how to easily create, deploy and manage both off-the-shelf and custom apps, improving productivity and efficiency for employees by mobilizing apps, processes... All Mobile/Wireless White Papers | Webcasts
Our weekly newsletter will cover a wide range of topics and trends related to consumerization. Stay up to date with news, reviews and in-depth coverage of BYOD, smartphones, tablets, MDM, cloud, social and how consumerization affects IT. Subscribe now!
