Free Republic
Browse · Search
General/Chat
Topics · Post Article

Skip to comments.

Android Malware Uses Built-In Firewall to Block Security Apps
SOFTPEDIA ^ | 28 Dec 2015, 18:45 GMT | Catalin Cimpanu

Posted on 12/28/2015 7:49:56 PM PST by Utilizer

Even if some malware families never get to cause worldwide damage, it's sometimes interesting to read about new techniques that some malware authors employ for creating their threats.

One of the most recent cases is a malware family that targets Android devices in China, discovered by Symantec, and named Android.Spywaller.

The uniqueness of this threat is the fact that during infection, the malware looks for Qihoo 360, a popular security app among Chinese Android users. Android.Spywaller uses a firewall to block Qihoo 360 internal communications

The malware searches and registers on the device with the same UID (unique identifier) used by the Qihoo 360 app, and then loads a binary called DroidWall, a version of the UNIX iptable package, modified to run on Android devices.

The iptable package is a well-known firewall utility for Linux systems, and DroidWall was developed by independent security researchers Rodrigo Rosauro, who later sold it to AVAST in 2011. Since the app spent a few years as open source, malware authors can still find it via Google Code or GitHub repositories.

(Excerpt) Read more at news.softpedia.com ...


TOPICS: Computers/Internet
KEYWORDS: android; malware; security; symantec; symc
Apparently not a major problem yet as it has so far only caused problems with Chinese users, this has the potential to spread from there so it is probably best to be aware of this problem. Looks more like trojanware, actually.
1 posted on 12/28/2015 7:49:56 PM PST by Utilizer
[ Post Reply | Private Reply | View Replies]

To: Utilizer
Android Malware Uses Built-In Firewall to Block Security Apps

I believe Conficker did that too.

2 posted on 12/28/2015 7:54:03 PM PST by Steely Tom (Vote GOP: A Slower Handbasket)
[ Post Reply | Private Reply | To 1 | View Replies]

To: Utilizer

Who creates these things, and why?

My guess is that the people who sell prevention and cures for them are responsible. Create a problem, sell a cure.


3 posted on 12/28/2015 9:58:38 PM PST by JimRed (Excise the cancer before it kills us; feed & water the Tree of Liberty! TERM LIMITS NOW & FOREVER!)
[ Post Reply | Private Reply | To 1 | View Replies]

To: Utilizer

If this is not on Google play store, it isn’t a threat to any sane Android user.


4 posted on 12/28/2015 11:06:44 PM PST by Dalberg-Acton
[ Post Reply | Private Reply | To 1 | View Replies]

To: Dalberg-Acton

You mean the same wankers that put the hope-’n-change Indonesian Muslim Community Organizer into office?

I’m willing to wager that many of them have Android devices, if not most of them. One could even imagine them possessing several in fact.


5 posted on 12/28/2015 11:16:12 PM PST by Utilizer (Bacon A'kbar! - In world today are only peaceful people, and the muzrims trying to kill them)
[ Post Reply | Private Reply | To 4 | View Replies]

To: Utilizer; ThunderSleeps

Ping for the Android Ping list. . .


6 posted on 12/29/2015 12:15:11 AM PST by Swordmaker (This tag line is a Microsoft insult free zone... but if the insults to Mac users continue....)
[ Post Reply | Private Reply | To 1 | View Replies]

To: Utilizer

You live by the pirated software, you die by it as well.


7 posted on 12/29/2015 2:06:48 AM PST by kingu (Everything starts with slashing the size and scope of the federal government.)
[ Post Reply | Private Reply | To 1 | View Replies]

To: 109ACS; aimhigh; bajabaja; Bikkuri; Bobalu; Bookwoman; Bullish; Carpe Cerevisi; DarthDilbert; ...
A scary "good" virus, one that will no doubt spawn imitators... - ANDROID PING!

Android Ping!
If you want on or off the Android Ping List, Freepmail me.

8 posted on 12/29/2015 3:57:55 PM PST by ThunderSleeps (Stop obarma now! Stop the hussein - insane agenda!)
[ Post Reply | Private Reply | To 1 | View Replies]

Disclaimer: Opinions posted on Free Republic are those of the individual posters and do not necessarily represent the opinion of Free Republic or its management. All materials posted herein are protected by copyright law and the exemption for fair use of copyrighted works.

Free Republic
Browse · Search
General/Chat
Topics · Post Article

FreeRepublic, LLC, PO BOX 9771, FRESNO, CA 93794
FreeRepublic.com is powered by software copyright 2000-2008 John Robinson