ZeroHour
The Recordpublished ()ingested

Android smartphones infected with rare rooting malware

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2019-2215
Use-After-Free Privilege Escalation in Android Kernel (CVE-2019-2215)

CVE-2019-2215 is a use-after-free flaw (CWE-416) in the Android kernel's binder.c IPC driver that allows privilege escalation from an application to the Linux kernel. Exploitation requires no user interaction, but an attacker must either run a malicious local application or chain the bug with a vulnerability in a network-facing application. Successful exploitation yields kernel-level code execution, effectively rooting the device and giving the attacker full control over apps, data, and communications. Affected parties include Android devices with unpatched kernels (reporting at the time indicated most Android phones were affected), plus products shipping affected Android kernel code, including Google Android, Debian/Ubuntu builds, and NetApp and Huawei offerings. The flaw was publicly disclosed and patched in Android's October 2019 security updates, public proof-of-concept exploits exist, and it is listed in CISA's Known Exploited Vulnerabilities catalog with a high (72.1%) EPSS probability of exploitation; headlines confirm in-the-wild use, including a Google Play app that leveraged it to deliver spyware.

Do: Apply vendor-supplied updates per CISA's required action — for phones and tablets, ensure the device is on the October 2019 Android security patch level or later (check Settings > About phone > Android security patch level) and patch via MDM across your fleet; NetApp, Huawei, Debian, and Ubuntu customers should install their vendors' corresponding kernel updates. Because this is a local privilege escalation with no user interaction required, also patch any network-facing applications that could be chained with it, and hunt for signs of exploitation such as unexpected root or unknown sideloaded/rooting apps on managed devices.

7.872% KEV PoC ×2
  • google android (Android kernel, binder.c)
  • huawei android (Android-based devices)
  • debian linux (Android kernel code)
  • +9 more
massbillions of devices
CVE-2020-0041
Out-of-Bounds Write in Android Kernel Binder Driver Enables Local Privilege Escalation

CVE-2020-0041 is an out-of-bounds write in the binder_transaction function of the Android kernel's binder.c, caused by an incorrect bounds check in the binder IPC driver. It is triggered locally: code already on the device, such as an unprivileged app or process, can issue a maliciously crafted binder transaction with no user interaction and no additional execution privileges required. A successful exploit escalates a local attacker from app-level privileges to kernel-level code execution, giving full read/write control of the device — the same type of primitive used by rooting malware seen in recent Android threats. Affected products are Android devices running kernel builds without the upstream binder fix; Google is the listed vendor, and because the flaw sits in the shared Android kernel it potentially spans many OEM device models rather than a single product. CISA added the CVE to the Known Exploited Vulnerabilities catalog on 2021-11-03, indicating known exploitation in the wild, though no public PoC is known and EPSS estimates roughly a 3% chance of exploitation in any 30-day window.

Do: Apply the kernel/binder patch by installing your device OEM's latest Android security update, consistent with CISA KEV's required action to apply updates per vendor instructions, and verify the device is on a current security patch level. There is no known mitigation short of patching the binder driver, so prioritize devices that install untrusted apps, where local attackers have an execution foothold. The rooting malware activity in recent headlines is not confirmed in this data to exploit CVE-2020-0041, but patching eliminates the kernel LPE primitive such malware relies on.

7.83% KEV
  • Google Android (kernel, binder driver) Android kernel builds without the upstream binder.c fix; CISA lists 'Android Android Kernel' with no specific kernel version ranges provided in the source data
mass≈ billions of Android devices potentially affected (Android's global active install base is on the order of 3 billion devices)
CVE-2020-0069
Out-of-Bounds Write in MediaTek Command Queue Driver Enables Android Privilege Escalation

CVE-2020-0069 is an out-of-bounds write (CWE-787) in the ioctl handlers of the MediaTek Command Queue kernel driver on Android, caused by insufficient input validation and missing SELinux restrictions. Any application running locally can trigger the flaw by sending maliciously crafted ioctl requests, and no special permissions or user interaction are required. A successful exploit corrupts kernel memory and achieves local escalation of privilege, giving the attacker root-level control of the device. Affected users are owners of Android phones built on the multiple MediaTek chipsets named by CISA, spanning Google Android and numerous Huawei/Honor firmware builds (including Honor 20 Pro, Nova 3, Y6 2019, and Berkeley/Columbia/Cornell/Dura firmware variants). The flaw is confirmed as exploited in the wild via CISA's KEV catalog (added 2021-11-03, with ransomware use listed as unknown), EPSS estimates a 1.4% probability of exploitation within 30 days, no public PoC is cataloged, and the KEV listing coincided with reports of rooting malware such as AbstractEmu capable of gaining root on Android devices.

Do: Apply the latest vendor firmware / Android security update per vendor instructions, as required by the CISA KEV entry, and verify the device shows a current Android security patch level in Settings > About phone. Because exploitation requires a locally installed app, avoid installing untrusted or sideloaded apps on unpatched MediaTek-based devices as an interim mitigation. Organizations should inventory MediaTek-powered handsets, including the listed Huawei/Honor models, and prioritize patching them given confirmed in-the-wild exploitation.

7.81% KEV
  • MediaTek Chipset list not enumerated in source data; affected Android kernel builds fixed via vendor security updates
  • Google Android Android kernel (affected Android release versions not enumerated in source data)
  • Huawei Berkeley-L09 firmware
  • +9 more
mass≈100M+ devices (order of magnitude: hundreds of millions of MediaTek-based Android handsets; exact count unknown)
Full article359 words · extracted from therecord.media · click to collapse

Security researchers at Lookout have discovered a new Android malware strain that contains the ability to root smartphones, a feature that has become quite rare in Android malware strains in recent years.

Named AbstractEmu, the malware and its distribution campaign have been detailed in a report published today, summarized below:

  • The AbstractEmu malware was distributed hidden inside 19 Android applications that were uploaded on Google Play, the Amazon Appstore, the Samsung Galaxy Store, and other unofficial third-party app stores.
  • Only one of the 19 apps, called Lite Launcher, reached the Google Play Store, where it was downloaded by only 10,000 users.
  • Once on a device, the AbstractEmu malware would download and execute one of five exploits for older Android security flaws that would allow it to root and take over the device.
  • The rooting package contained exploits for the following five vulnerabilities: CVE-2020-0041, CVE-2020-0069, CVE-2019-2215, CVE-2015-3636, and CVE-2015, 1805.
  • Once the AbstractEmu malware gains elevated privileges following the rooting exploit, it would give itself access to dangerous permissions, and then access additional malware components on the devices.
  • After a device is infected, the following data is collected and sent to a remote server.
  • Lookout said it was unable to determine what malicious operations this malware would carry out but said that based on the permissions the malware assigned itself, there were similarities with banking trojans and spyware-focused threats such Anatsa, Vultur, and Mandrake.
  • The company described the malware's creators as a "well-resourced group with financial motivation."
  • Lookout said it named the malware AbstractEmu because of its use of code abstraction and anti-emulation checks to avoid running while under analysis and sandboxes.

The names of some of the apps and their installation packages –discovered to contain the AbstractEmu malware– are below:

TitlePackage name
All Passwordscom.mobilesoft.security.password
Anti-ads Browsercom.zooitlab.antiadsbrowser
Data Savercom.smarttool.backup.smscontacts
Lite Launchercom.st.launcher.lite
My Phonecom.dentonix.myphone
Night Lightcom.nightlight.app
Phone Pluscom.phoneplusapp

No previous article

No new articles

Catalin Cimpanu

is a cybersecurity reporter who previously worked at ZDNet and Bleeping Computer, where he became a well-known name in the industry for his constant scoops on new vulnerabilities, cyberattacks, and law enforcement actions against hackers.

Text extracted automatically; images, tables and formatting may be missing. Original: https://therecord.media/android-smartphones-infected-with-rare-rooting-malware