ie8 fix
madison

Zero Day

Ryan Naraine, Emil Protalinski and Dancho Danchev

Malware sneaks by Google's Android Market gatekeepers again

By | May 31, 2011, 12:11pm PDT

Twenty-six apps containing malware moved onto the Android Market over the weekend, according to Lookout Mobile Security.

In a blog post, Lookout said that it appeared that the malware was created by the same developers that launched DroidDream in March. Lookout added:

26 applications were found to be infected with a stripped down version of DroidDream we’re calling “Droid Dream Light” (DDLight). At this point we believe between 30,000 and 120,000 users have been affected by DroidDreamLight.

The malware compromises personal data and further highlights that Android’s Wild West-ish marketplace can be a significant handicap. The last time around, Google pulled the Android apps with malware and uninstalled them from phones.

The 26 apps come from Magic Photo Studio, Mango Studio, E.T. Tean, BeeGoo and DroidPlus.

These apps have components that are launched during incoming voice calls. There’s no need for a manual launch.

Google has to nail these malware apps down and block them at the gate. If not more curated efforts from the likes of Amazon are likely to be used.

Related:

Kick off your day with ZDNet's daily e-mail newsletter. It's the freshest tech news and opinion, served hot. Get it.

Topics

26
Comments

Join the conversation!

Just In

RE: Malware sneaks by Google's Android Market gatekeepers again
dunners6 12th Jul
Pretty stupid missleading title.
The Android market doesn't have "gatekeepers" it's Apple who sorts which apps you can and can't have.
Handicap how? Each app clearly states what access it gives to your device.

If you install it, you do it at your own risk. Stick to trusted publishers and apps and you would never have an issue.
@Droid101 You're wasting your time man, these are people who would rather have the perception of Safety than Freedom.
@Peter Perry
And some would rather have the perception of freedom and no safety. Google is slowly constricting Android people are defending it because they have the freedom to do what Google allows.
@Peter Perry
what driod 101 said is absolutely right ,, on their own risk one should down the app an install,,actually there are plenty f apps and app publishers ,,,,,
http://thenewscourier.blogspot.com/2011/06/google-faces-new-trouble-from-android.html
@Droid101: Clear? By your standards, not everyone is technical. It's just a list of what it will give access too.

Besides it's up to the OS to protect the user, not the user protect the OS.

Why do both Microsoft and Apple ship their Desktop OS's with the firewall enabled? It shouldn't be needed, it's up to the user what they download and where they visit right?

It's up to them to protect their users from themselves.
@bradavon
I can't help but notice that you contradicted yourself.
"it's up to the OS to protect the user, not the user protect the OS"
Then
"it's up to the user what they download and where they visit"

It's the responsibility of the user to protect their computer (Smartphone) from malware. You can have the best firewall in the world and still get malware/virus'/Trojans etc.. if your not careful.

And this applies to all OS' mobile and desktop.
@dunners6 The second one was a question, not a statement.
@Droid101 Funny... When that same advice was given to Mac users regarding how not to get MacDefender... everyone flipped out because it was "unreasonable" and the OS should be secure even when users get tricked into installing Malware.
0 Votes
+ -
Message has been deleted.
TechExpert21 Updated - 1st Jun
  • Flagged
@eak2000 Yeah, I was absolutely amazed at the hypocrisy when comparing the malware issues of OSX and the Android Market. It's estimated that 30K-120K individuals have been affected by DDlight, were that many affected by MacDefender? Honest question as I have not seen that stat. Of course there will probably be 10 articles about MacDefender for every article about DDLight.
@Droid101

You mean don't use anything open source. Sad...
@Droid101 And how is the majority supposed to know who is a trusted publisher. I bet you are a droid developer aren't you.
@Droid101 Never mind that this is supposed to be a trusted repository for Android Apps... whatever dude.
0 Votes
+ -
@Droid101

So what is the point of being "open" then? The apologies run high in your family. You have it. ....
"The last time around, Google pulled the Android apps with malware and uninstalled them from phones."
Google, please teach MS that trick!
@cybr2th@... Windows mobile 7 has never gotten malware yet. Don't need to know what trick. They curate their store.
@tymiles That's just like the Apple OS arguement. "There's no malware on our computers because no one has them."
@tymiles
yea! no one has a Win Mobile 7 phone. And no one write for one either. I have one and cant get the apps Droid or Ios has for that very reason.
"These apps have components that are launched during incoming voice calls."
I take back my complaints about the Samsung Galaxy Tab not having telephony.
0 Votes
+ -
Message has been deleted.
TechExpert21 Updated - 1st Jun
0 Votes
+ -
Message has been deleted.
TechExpert21 Updated - 1st Jun
What do I think?

Umm, TechExpert21 repeats him(-surely not her)self an awful lot?
Anyone who would actually use a phone app to keep personal data, especially passwords and financial information, needs their head examined.
0 Votes
+ -
Just Nuts
GAstorino@... 1st Jun
How is one supposed to know that an app is safe when you are buying from a Google Store. If I buy apples at the grocery store and the food is poisoned then am I the one responsible for eating the poisoned apple and not the store for selling it? I have been hacked by Apple Itunes as well buying an app from a supposed reputable seller who has many recommendations - himself and friends and then find out its a fake with many complaints and Apple still has them selling their fake wares so who should be responible the unsuspecting shopper or the company selling the apps.
Ha Ha - and THIS is the company who just announced they intend to develop "electronic wallets", and on the SAME risky Android platform, no less????? What part of "Run away, run away" do we not grasp???
Pretty stupid missleading title.
The Android market doesn't have "gatekeepers" it's Apple who sorts which apps you can and can't have.

Join the conversation!

Formatting +
BB Codes - Note: HTML is not supported in forums
  • [b] Bold [/b]
  • [i] Italic [/i]
  • [u] Underline [/u]
  • [s] Strikethrough [/s]
  • [q] "Quote" [/q]
  • [ol][*] 1. Ordered List [/ol]
  • [ul][*] · Unordered List [/ul]
  • [pre] Preformat [/pre]
  • [quote] "Blockquote" [/quote]
ie8 fix
Click Here
ie8 fix

The best of ZDNet, delivered

ZDNet Newsletters

Get the best of ZDNet delivered straight to your inbox

Facebook Activity

White Papers, Webcasts, & Resources
ie8 fix
ie8 fix