Crooks Use Google’s Own Cloud To Control Android Malware

Cyber criminals are controlling Android malware using Google’s own cloud, helping them update bad apps to add fresh functionality without being blocked.

A host of typical Android malware is being updated via Google Cloud Messaging, a service that lets developers send data, such as advertising information, small messages and commands, to users of their applications.

As GCM is an official Google service, it is  impossible to block updates directly on an infected device, Kaspersky Lab warned. Developers have to get a unique ID from Google to use GCM, indicating Google is unwittingly granting them to cyber crooks.

Abusing Google to control Android malware

The criminals use GCM to initiate updates, advertise other malicious programs or have infected devices send text messages. Effectively, the Google cloud is exploited to become part of the attackers’ command and control infrastructure.

Fakelnst.a Trojan, one of the most prevalent Android threats that sends text messages to premium numbers and can delete incoming text messages, is registered with GCM. That particular malware is prevalent in Russia, and Kaspersky said it had detected over 4.8 million Fakelnst.a installers to date.

The Agent.ao malware, which is prevalent in the UK, used GCM to retrieve updates and create notifications with information or advertising content.

Many of the bad applications are pornography sites, and none are on the official Google Play market. Users are advised to only download apps from trusted sources.

“The execution of commands received from GCM is performed by the GCM system and it is impossible to block them directly on an infected device,” said Kaspersky Lab expert Roman Unuchek, in a blog post.

“The only way to cut this channel off from virus writers is to block developer accounts with IDs linked to the registration of malicious programs.”

What do you know about Internet security? Find out with our quiz!

Thomas Brewster

Tom Brewster is TechWeek Europe's Security Correspondent. He has also been named BT Information Security Journalist of the Year in 2012 and 2013.

Recent Posts

Russia Accused Of Cyberattack On Germany’s Ruling Party, Defence Firms

German foreign minister warns Russia will face consequences for “absolutely intolerable” cyberattack on ruling party,…

17 hours ago

Alphabet Axes Hundreds Of Staff From ‘Core’ Organisation

Google is reportedly laying off at least 200 staff from its “Core” organisation, including key…

17 hours ago

Apple Announces Record Share Buyback, Amid iPhone Sales Decline

Investor appeasement? Apple unveils huge $110 billion share buyback program, as sales of iPhone decline…

21 hours ago

Tesla Backs Away From Gigacasting Manufacturing – Report

Tesla retreats from pioneering gigacasting manufacturing process, amid cost cutting and challenges at EV giant

2 days ago

US Urges No AI Control Of Nuclear Weapons

No skynet please. After the US, UK and France pledge human only control of nuclear…

2 days ago