ANDROIDOS_SHUAME.OPSA
October 15, 2015
PLATFORM:
Android
OVERALL RISK RATING:
DAMAGE POTENTIAL:
DISTRIBUTION POTENTIAL:
REPORTED INFECTION:
INFORMATION EXPOSURE:
Threat Type: Rootkit
Destructiveness: No
Encrypted:
In the wild: Yes
OVERVIEW
This rootkit takes advantage of certain vulnerabilities.
TECHNICAL DETAILS
Download Routine
After successfully exploiting the said vulnerability, this malware connects to the following URLs to possibly download other malicious files:
- http://adservice.{BLOCKED}eapp.com/root/getAdList.json
Other Details
This rootkit takes advantage of the following vulnerabilities:
- Android API Function Address Validation Vulnerability (CVE-2013-6282)
- Linux Kernel Futex Local Privilege Escalation (CVE-2014-3153)
- Android <5.0 Privilege Escalation using ObjectInputStream (CVE-2014-7911)
- Linux Kernel Ping_Unhash Function Vulnerability (CVE-2015-3636)
- Memory Corruption in QSEECOM Driver (CVE-2014-4322)