+

Cookies on the Business Insider India website

Business Insider India has updated its Privacy and Cookie policy. We use cookies to ensure that we give you the better experience on our website. If you continue without changing your settings, we\'ll assume that you are happy to receive all cookies on the Business Insider India website. However, you can change your cookie setting at any time by clicking on our Cookie Policy at any time. You can also see our Privacy Policy.

Close
HomeQuizzoneWhatsappShare Flash Reads
 

Hackers Have Built Their Own Mobile Ad Networks That Install Malware Onto Your Phone

Aug 13, 2013, 19:27 IST

Kara Allyson via Flickr Hackers are building their own legitimate-looking mobile ad networks that allow malware into people's phones through a back door. The new ploy takes advantage of app developers' desperate need to monetize their apps. Once the app links to the malicious ad network and serves an ad, the users' phone is infected. At that point, the malware usually begins racking up premium text service charges.

Advertisement

The new twist is that the malware is triggered by the app developer including the ad network's code in its app, not by the user downloading something dodgy.

Here's how it works. Normally, app developers include software development kits (SDKs) for a variety of a networks in their apps. This allows ads to be served on behalf of the highest bidder across a range of ad networks. The SDK serves the ads to users, and the developer and the network split the fee, according to Christian Science Monitor:

Unfortunately, how well developers vet the ad networks they side with varies from one app maker to another. If the developer does not care or simply goes with the highest bidder, then the chances of siding with a malicious ad network is high.

The malicious SDK then sits in the background, and waits until the user downloads another app. When that happens, the malware inserts an extra dialog box during the new app download, asking the user for permission to access text/SMS services. A little while later, the user finds a bunch of premium charges for text use on their bill.

Advertisement

Wade Williamson, a senior security analyst with Palo Alto Networks in Santa Clara, Calif., said malicious mobile ad networks take advantage of app developers who need the cash from ads:

"This is where things get extremely interesting," Williamson said in an interview. "The issue is that for pretty much anybody who builds a mobile application, they don't make much money from the application, so they have to build in these hooks to the mobile ad networks. What happens is those ad networks are more or less behaving like crude botnets."

Williamson has seen seven malicious ad networks so far, mainly from China and Asia.

Here's a look at the top mobile ad networks and the top malware devices they serve, courtesy of Trend Micro:

Trend Micro

Advertisement
You are subscribed to notifications!
Looks like you've blocked notifications!
Next Article