Android malware gives itself root access

Google Android
Your 'droid could be making unauthorised calls

A piece of Android malware has been discovered that steals money by giving itself root access then connecting to a botnet to make premium rate texts and calls.

The malware has been named RootSmart by the research team led by Xuxian Jiang, assistant professor of NC State University's department of computer science.

Hiding in an Android app named com.google.android.smart, which uses the default system settings icon, it waits for certain events like an outgoing call before setting to work.

It then connects to its command-and-control server and downloads the GingerBreak root exploit. That done, it automatically gains root access to the phone, allowing it to install additional apps which get to work making money via premium rate texts and calls.

Made in China

Currently, it appears to be targeting users of just two Chinese mobile networks, and researchers have only found the malware on third-party download sites, rather than the official Android Market.

At this time it only affects devices running Android Gingerbread versions earlier than 2.3.4 or Android Honeycomb 3.0.

Symantec estimates that RootSmart is generating between £1,000 and £5,500 in revenue every day.

Google has recently upped its efforts to combat Android malware with its Bouncer programme, but it always pays to be vigilant.

Jiang recommends paying attention to permissions requested by apps, looking out for devices behaving strangely and running up-to-date security software.

From Xuxian Jiang via Information Week, The Verge

TOPICS
Latest in Android
Android 16 logo on a phone
Android 16 Beta 3 has arrived – here are the 4 features I think will be the most useful
Google Pixel 9
Android 16 could bring an improved Samsung DeX-style desktop mode to more phones
Android 16 logo on a phone
Android 16 beta users are reporting major battery drain issues – but I’m not too worried about it
The Oppo Find N5 open to Google Maps
Android 16 brings a much-needed upgrade to Google Maps that iOS users already have
A hand holding a phone showing the Android Find My Device network
Android's Find My Device can now let you track your friends – and I can't decide if that's cool or creepy
Android 15 logo on a phone, in a hand
Google is working on its own version of Apple’s Hide My Email, and you might soon be able to try it yourself
Latest in News
Panos Panay and Alexa Plus
Amazon's Panos Panay teases future Alexa+ devices from speakers to possible wearables
Metroid Prime 4
I reckon the Nintendo Switch 2 could launch with Metroid Prime 4 – here’s why
Samsung Galaxy Z Fold 6
New rumors predict a foldable iPhone will launch next year – and cost almost twice as much as the iPhone 16 Pro Max
Pebble smartwatch countdown
Pebble confirms its smartwatch announcement is just hours away
Logo of YouTube Shorts
Is YouTube auto-playing Shorts when you open the app? Well, you’re not alone - here’s how to fix it
Google DeepMind panel discussion
“More sovereignty and protection” - Google goes all-in on UK AI with data residency, upskilling projects, and startup investments