AndroidOS_Janus.ISO

 Analysis by: Song Wang

 PLATFORM:

Android

 OVERALL RISK RATING:
 DAMAGE POTENTIAL:
 DISTRIBUTION POTENTIAL:
 REPORTED INFECTION:
 INFORMATION EXPOSURE:

  • Threat Type: Exploit

  • Destructiveness: No

  • Encrypted:

  • In the wild: Yes

  OVERVIEW

Infection Channel:

Dropped by other malware, Downloaded from app stores/third-party app stores

This Exploit may be dropped by other malware. It may be downloaded from app stores/third party app stores.

  TECHNICAL DETAILS

Payload:

Exploits vulnerabilities

Arrival Details

This Exploit may be dropped by other malware.

It may be downloaded from app stores/third party app stores.

Mobile Malware Routine

This Exploit is capable of doing the following:

  • The Janus vulnerability (CVE-2017-13156) could allow attackers to modify installed apps without affecting their signature. This would allow an attacker to remotely gain access to the affected device.

NOTES:

A malware can abuse this vulnerability in two ways. 1. It can be used to hide a payload. Malware may disguise itself as a single clean DEX file, with the malicious payload stored in the APK file to be loaded later. 2. It can be used to update an already installed app with the malicious payload (in the updated application version).

  SOLUTION

Minimum Scan Engine:

9.850

Trend Micro Mobile Security Solution

Trend Micro Mobile Security Personal Edition protects Android and iOS smartphones and tablets from malicious and Trojanized applications. It blocks access to malicious websites, increase device performance, and protects your mobile data. You may download the Trend Micro Mobile Security apps from the following sites:


Did this description help? Tell us how we did.