It appears you have not yet registered with our community. To register please click here...

 
Go Back [M] > Madshrimps > WebNews
Russians hit Android in the backdoor Russians hit Android in the backdoor
FAQ Members List Calendar Search Today's Posts Mark Forums Read


Russians hit Android in the backdoor
Reply
 
Thread Tools
Old 1st September 2023, 10:19   #1
[M] Reviewer
 
Stefan Mileschin's Avatar
 
Join Date: May 2010
Location: Romania
Posts: 148,802
Stefan Mileschin Freshly Registered
Default Russians hit Android in the backdoor

Infamous Chisel replaces system components

Western intelligence agencies said Russia's military intelligence unit has been targeting Ukrainian Android devices with "Infamous Chisel."

For those who came in late, Infamous Chisel is the tracking name for new malware designed to backdoor devices and steal critical information. It is a collection of components that enable persistent access to an infected Android device over the Tor network and which periodically collates and exfiltrates victim information from compromised devices.

“Five eyes” Intelligence officials from the UK, US, Canada, Australia, and New Zealand warn that the information exfiltrated is a combination of system device information, commercial application information and applications specific to the Ukrainian military."

Infamous Chisel gains persistence by replacing the legitimate system component known as netd with a malicious version. Besides allowing Infamous Chisel to run each time a device is restarted, the malicious netd is also the main engine for the malware.

It uses shell scripts and commands to collate and collect device information and also searches directories for files with a predefined set of extensions. Depending on where on the infected device a collected file is located, netd sends it to Russian servers either immediately or once a day. Infamous Chisel uses the TLS protocol and a hard-coded IP and port when exfiltrating files of interest.
https://fudzilla.com/news/57517-russ...n-the-backdoor
Stefan Mileschin is offline   Reply With Quote
Reply


Similar Threads
Thread Thread Starter Forum Replies Last Post
OnePlus kills off backdoor Stefan Mileschin WebNews 0 16th November 2017 19:13
Foxconn installs Pork Explosion backdoor into Android gear Stefan Mileschin WebNews 0 15th October 2016 14:19
Facebook was the victim of a backdoor hack Stefan Mileschin WebNews 0 24th April 2016 15:00
Apple already has a backdoor in iOS Stefan Mileschin WebNews 0 19th February 2016 08:38
Bunk Baidu SDK puts backdoor on millions of Android devices Stefan Mileschin WebNews 0 4th November 2015 09:18
The US government won't force backdoor access, but still wants it Stefan Mileschin WebNews 0 11th October 2015 15:51
RSA didn't let the NSA in through the backdoor Stefan Mileschin WebNews 0 24th December 2013 14:47
Ubsoft DRM ships with backdoor Stefan Mileschin WebNews 0 1st August 2012 08:49
New Mac OS X backdoor discovered Stefan Mileschin WebNews 0 5th July 2012 07:08
Opening the TiVo Backdoor jmke WebNews 0 1st June 2005 16:25

Thread Tools

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are Off
Pingbacks are Off
Refbacks are Off


All times are GMT +1. The time now is 10:31.


Powered by vBulletin® - Copyright ©2000 - 2024, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO