A new Trojan is targeting Android devices. Known in security circles as Geinimi, the Trojan is powerful enough to compromise the personal data on a user’s smartphone and send it to remote servers.
So says Lookout Mobile Security. In fact, the firm said the new Trojan is the most sophisticated Android malware its security researchers have seen to date. What’s more, Geinimi is also the first Android malware in the wild that displays botnet-like capabilities. That means once the malware is installed on a user’s phone, it has the potential to receive commands from a remote server that allow the owner of that server to control the phone.
“Geinimi is effectively being ‘grafted’ onto repackaged versions of legitimate applications, primarily games, and distributed in third-party Chinese Android app markets,” the company wrote in a blog post. “The affected applications request extensive permissions over and above the set that is requested by their legitimate original versions.”
Apple’s Advantage
Lookout said the Trojan’s intent isn’t entirely clear, but the possibilities range from a malicious ad network to an attempt to create an Android botnet.
Here’s how it works: When a host application containing Geinimi is launched on a user’s phone, the Trojan runs in the background and collects information that can compromise a user’s privacy, Lookout said. That includes location coordinates and unique identifiers for both the device and SIM card. At five-minute intervals, Lookout explains, Geinimi attempts to connect to a remote server using one of 10 embedded domain names. If it connects, Geinimi transmits collected information to the remote server.
“This is unlikely to affect end users in the U.S. You have to go to a third-party site and enable and install third-party applications outside the marketplace. But it underscores the Wild West nature that is the Android platform,” said Michael Gartenberg, an analyst at…