‘Android Security Suite Premium’ App is Malware in Disguise

Android Security Suite Premium Icon

If you’re an Android user, there’s a good chance that you’ve caught a headline or two warning about the latest piece of malware targeting the mobile OS, and are now considering downloading a security app to add another layer of protection to your device.

Should this be the case, just make sure that you don’t inadvertently download malware masquerading as a mobile security application in the process.

Researchers at both Kaspersky Lab and Webroot recently found that a security app named “Android Security Suite Premium” was anything but what the name implied, as it adhered to the demands of its villainous command & control (C&C) server.

Such commands usually entailed stealing incoming SMS messages – possibly along with other system information – and relaying that information back to the attackers.

In analyzing six samples of the bogus security app, Kaspersky Lab discovered 6 different C&C domains encoded within them, one of which had been registered with the same fake data as ZeuS C&C domains.

It is for this reason that the “Android Security Suite Premium” app has earned title as the latest variant of ZitMo (short for ‘Zeus in the Mobile’) trojans.

Kaspersky Lab did not disclose where they had retrieved their APK samples; however, researchers over at Webroot found the Android Security Suite Premium app lurking in torrents and/or third-party Android markets.

So, if you’re on the hunt for a legitimate mobile security app, it is suggested that you:

  • Download the app from the official Google Play store.
  • Check the developer name, number of downloads and most important of all, user reviews.

It is worth noting that majority of PC antivirus vendors also offer a mobile security solution, so it may be best to do a little research before searching the Google Play store so you can verify the company’s Google Play developer name, app permissions and the like.

Screenshot Credit: Kaspersky Lab

Don’t miss out on the latest tech news and computer security alerts! Follow us on Twitter at @hyphenet,  “Like” us on Facebook or add us to your circle on Google+

This entry was posted in Computer Security, malware and tagged , , , , , .
Follow any comments here with the RSS feed for this post. Post a comment or leave a trackback: Trackback URL.

© 2014 Hyphenet, Inc.
1761 Hotel Circle S, Suite 350, San Diego, CA 92108

All rights reserved. Reproduction in whole or in part in any form or medium without express written permission is prohibited.

Hyphenet IT Security Blog located at 1761 Hotel Circle South, Suite 350 , San Diego, CA . Reviewed by 91 customers rated: 3.8 / 5