ESET researchers have recently discovered a Turkish alternative Android app that has been spreading malware across all android apps.
ESET researchers discovered that CepKutusu.com, a Turkish alternative Android app store was spreading malware under the guise of all offered Android apps.
When users browsed the Turkish alternative app store CepKutusu.com and proceeded to downloading an app, the “Download now” button led to banking malware instead of the desired app. A few weeks after ESET researchers turned to the store’s operator with the discovery of the attack, the store ceased the malicious activity.
Interestingly, although ESET researchers found the misdirection from a legitimate app to the malicious one to be general – meaning that every single app was set to be replaced with the banking malware, the crooks behind the campaign added an exception. Probably to increase the chance to stay longer under the radar, they introduced a seven-day window of not serving malware after a malicious download. In practice, after the user downloads the infected app, a cookie is set to prevent the malicious system from prevailing, leading to the user being served clean links for next seven days. After this period passes, the user gets redirected to malware once they try to download any application from the store.
The malicious app distributed by the store at the time of the investigation was remotely controlled banking malware capable of intercepting and sending SMS, displaying fake activity, as well as downloading and installing other apps.
When installed, the malware doesn’t mimic the app the user intended to install. Instead, it imitates Flash Player.
To gain more insight on this attack and its wider implications, we turned to Lukáš Štefanko, Malware Researcher at ESET, who specializes in Android malware and who discovered the malware-distributing app store.
An app store serving its customers with malware on a mass scale – that sounds like a big threat. On the other hand, serving Flash Player instead of whatever customers wanted – that’s a rather thin disguise… What’s your take on this?
First, let me say that this is the first time I’ve seen an entire Android market infected like that. Within the Windows ecosystem and in browsers, this technique is known to have been used for some time but in the Android ecosystem, it’s really a new attack vector.
As for the impact, what we saw in this particular case was most probably a test. The crooks misused their control of the app store in the simplest manner. Replacing the links to all apps with a link to a single malicious app requires virtually no effort – but it also gives the store’s customers a fair chance to detect the scam. If you got lured into downloading a popular game and ended up with Flash Player instead… I think you’d uninstall it straight away and report the issue, right?
This might explain why we have seen only a few hundred infections.
From this point of view, it doesn’t sound like a big deal …
Well, like I said, it was probably a test. I can imagine a scenario in which the crooks who control the store’s back end append a malicious functionality to each of the apps in the store. Serving those interested in a particular game with a trojanized version of that game… That would remove the biggest red flag and the number of victims might rise significantly.
As for the attribution of this attack – have you found any traces?
There are three possible scenarios here: an app store built with the intention to spread malware; a legitimate app store turned malicious by an employee with bad intentions; and a legitimate app store becoming a victim of a remote attacker.
As for scenarios two and three, I would think that such an attack wouldn’t go unnoticed by a legitimate store. User complaints, suspicious server logs and changes in code should be sufficient indicators for its operators…. The more that the malware was being distributed via the store for weeks. Also of interest in this regard is that we contacted the store operators with our findings but haven’t received any reaction.
How to protect yourself
Recommendations by ESET
· If possible, always favor downloading apps from official app stores.
This piece of advice is infinitely repeated for a good reason – there’s no guarantee of any security measures in alternative app stores, making them a great place for malware authors to spread their “work”, and not just via single malicious apps, but also on a mass scale, as illustrated in this case.
· Be cautious when downloading content from the internet. Pay attention to anything suspicious in file name, size and extension – this is where many threats can still be recognized and avoided in time.
· Use a reliable mobile security solution to protect you from the latest threats. As for the threat hidden in the alternative app store, ESET detects it as Android/Spy.Banker.IE and prevents it from getting downloaded.
Huawei goes ultra-premium
Porsche Design and Huawei have launched the Porsche Design Huawei Mate RS in South Africa exclusive to MTN and retailing for R 26 459.
The Porsche Design Huawei Mate RS boasts features like the world’s first dual fingerprint design, including an in-screen fingerprint sensor, the world’s first Artificial Intelligence (AI) processor and Leica triple camera with 40MP image capture.
“After the overwhelming success of the Porsche Design Huawei Mate 10 Pro in South Africa, we now bring you our latest offering, a perfect blend of innovation in a smartphone and luxury design,” said Likun Zhao, Vice President of Huawei Consumer Business Group Southern Africa. “From three-point security feature including facial recognition, rear fingerprint scanner and the new innovative in-screen fingerprint to the Leica triple camera system. it culminates in an unprecedented experience for our customers.”
The device incorporates Porsche Design’s signature design language and Huawei’s breakthrough technology. The phone has a 6” 2K curved OLED screen and symmetrical look, minimalist feel and 8-edged 3D curved glass body.
High performance is symbolised by the naming of the smartphone: the term “RS” in the world of Porsche motorsport stands for outstanding racing performance.
Huawei provided the following information on The Porsche Design Huawei Mate RS benefits and features :
· The world’s first dual fingerprint scanner for enhanced convenience, allowing users to wake and unlock the device simply, thanks to an in-screen fingerprint sensor. Hover to wake the device, touch to unlock it
· The winning combination of Leica triple camera with 40MP RGB sensor technology and exceptional photography powered by Master AI. This combination puts effortless, eye-catching photography at the fingertips of those looking to immortalise their favourite moments. Combined with 5 x hybrid zoom, and the world’s first AI image stabilisation on a smartphone camera ensures photography lovers can capture the best shots with exceptional clarity in almost any situation
· The Porsche Design Huawei Mate RS is the first Huawei handset to allow quick wireless charging, making it even easier to keep the phone topped up and ready to go and, thanks to its long lasting battery, users will easily be powered through the busiest of days
· An ‘intelligent’ smartphone, the powerful AI processor automatically tailors the performance of the phone according to how it is used – constantly learning, understanding and anticipating needs, it is the perfect personal assistant for the pocket
· 256GB of internal storage means those constantly on the go and constantly on their phone can be worry free
· Dual SLS (super linear system) speakers with DOLBY ATMOS enable users to have a superior experience, with the best immersive surround sound and entertainment on the go
· Splash, water and dust resistant, which means there is no need to worry about damaging the device in the rain or accidentally dropping it in water
Jan Becker, CEO Porsche Design Group, said: “Both Porsche Design and Huawei seek to imagine and develop products that stand for precision and perfection, intelligent functionality and highly sophisticated design. Our aim was to create an outstanding device that goes one step further. We believe we have reached this goal by taking our partnership to the next level.”
Porsche Design and Huawei have worked in tandem to develop a smartphone that fuses together the two brands’ DNA, wealth of experience in design and technology, industry-leading expertise and exceptional performance. Through the use of colour in the device’s body, software themes and accessories, the new handset is accentuated with Porsche Design’s distinguished aesthetic and purist, minimalist feel.
The Porsche Design Huawei Mate RS will be available to purchase exclusively from MTN at R 26 459.
Cross-channel chat launched
Clickatell has launched a cross-channel live chat service, Touch Go, that transforms omni-channel customer care.
It enables live chat across a company’s website as well as social platforms (Twitter and Facebook) and mobile apps, bringing customer care and engagement into a single business platform.
“Today’s consumers expect to engage with your brand on the digital channel of their choosing,” says Deon van Heerden, Clickatell Engage CEO and Group CFO. “They want to message your business and instantly have queries resolved, find the information and services they are looking for, without the need for a voice call. Clickatell’s Touch Go makes that happen with the right level of capabilities for businesses of all sizes.”
Businesses can start using Touch Go immediately, with a free Starter option. Touch Go requires no credit card for sign-up and is fully featured with a simple setup process. It offers customisable branding, a unified chat desk business application as well as reports and analytics.
As the business scales up its digital customer care, it can opt-in for the Touch Enterprise offering. Touch Enterprise is designed for scaling up customer care efforts through advanced capabilities including AI driven virtual agents, sentiment analysis, automated workflows, enterprise integrations and in-channel mini-applications.
“Customer care has become a defining factor for sustained business success ” says Nirmal Nair, Clickatell Engage EVP Product & Marketing. “In an ever-increasing mobile native world, customers often choose to interact digitally, but they also expect to be able to reach a human immediately, should they need. Monitoring multiple channels and providing immediate action becomes challenging with siloed deployments. Touch’s unified solution allows businesses of all sizes to provide the customer delight in a simple modular approach.”