Geinimi Trojan targeting Android

 Dr.WEB, Russian developer of information security software, has updated the installer module in the eighth version of Dr.Web Security Space and Dr....
Apr 10 2013
McAfee, Inc., the world’s largest dedicated security company...
The first Patch Tuesday of 2010 is very light for Microsoft with a...
The new version of F-PROT Antivirus for Linux. The program is...
Most people are careful to shred their financial documents and keep...
Using the intelligence from the Websense ThreatSeeker Network,...
Lavasoft analysts anticipate the top five trends that will dominate...

The Lookout firm specializing in the security of mobile devices, has spotted a new Trojan targeting smartphones in China on Android.

Called Geinimi it would behave in the manner of a botnet receiving execution commands from a dozen remote servers. This malware hide in legitimate applications from the Android Market re-compiled - like games - and distributed directories third in China.

Geinimi would be able to recover more data and connect to remote servers. For example it is capable of exploiting the GPS chip and return the location to send the ID of the phone IMEI, download and request the installation of an application to request the removal of a component or yet to return a list of applications installed on the smartphone. Still, to install a title that is not part of the official Android Market, the mobinaute will still have to configure an authorization within the parameters of the mobile. Moreover, the process takes several confirmations to the user.

Communication with servers and data transfer would be made every five minutes. Experts believe it could be that Geinimi is the result of a network of malicious advertisements. Among the games distributed pox on Chinese websites include: Monkey Jump 2, President vs. Aliens, City Defense or Baseball Superstars 2010.

Add new comment