This New Android Malware Can Gain Root Access to Your Smartphones
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2019-2215 | Use-After-Free Privilege Escalation in Android Kernel (CVE-2019-2215) CVE-2019-2215 is a use-after-free flaw (CWE-416) in the Android kernel's binder.c IPC driver that allows privilege escalation from an application to the Linux kernel. Exploitation requires no user interaction, but an attacker must either run a malicious local application or chain the bug with a vulnerability in a network-facing application. Successful exploitation yields kernel-level code execution, effectively rooting the device and giving the attacker full control over apps, data, and communications. Affected parties include Android devices with unpatched kernels (reporting at the time indicated most Android phones were affected), plus products shipping affected Android kernel code, including Google Android, Debian/Ubuntu builds, and NetApp and Huawei offerings. The flaw was publicly disclosed and patched in Android's October 2019 security updates, public proof-of-concept exploits exist, and it is listed in CISA's Known Exploited Vulnerabilities catalog with a high (72.1%) EPSS probability of exploitation; headlines confirm in-the-wild use, including a Google Play app that leveraged it to deliver spyware. Do: Apply vendor-supplied updates per CISA's required action — for phones and tablets, ensure the device is on the October 2019 Android security patch level or later (check Settings > About phone > Android security patch level) and patch via MDM across your fleet; NetApp, Huawei, Debian, and Ubuntu customers should install their vendors' corresponding kernel updates. Because this is a local privilege escalation with no user interaction required, also patch any network-facing applications that could be chained with it, and hunt for signs of exploitation such as unexpected root or unknown sideloaded/rooting apps on managed devices. | 7.8 | 72% | KEV PoC ×2 |
| massbillions of devices | |
| CVE-2020-0041 | Out-of-Bounds Write in Android Kernel Binder Driver Enables Local Privilege Escalation CVE-2020-0041 is an out-of-bounds write in the binder_transaction function of the Android kernel's binder.c, caused by an incorrect bounds check in the binder IPC driver. It is triggered locally: code already on the device, such as an unprivileged app or process, can issue a maliciously crafted binder transaction with no user interaction and no additional execution privileges required. A successful exploit escalates a local attacker from app-level privileges to kernel-level code execution, giving full read/write control of the device — the same type of primitive used by rooting malware seen in recent Android threats. Affected products are Android devices running kernel builds without the upstream binder fix; Google is the listed vendor, and because the flaw sits in the shared Android kernel it potentially spans many OEM device models rather than a single product. CISA added the CVE to the Known Exploited Vulnerabilities catalog on 2021-11-03, indicating known exploitation in the wild, though no public PoC is known and EPSS estimates roughly a 3% chance of exploitation in any 30-day window. Do: Apply the kernel/binder patch by installing your device OEM's latest Android security update, consistent with CISA KEV's required action to apply updates per vendor instructions, and verify the device is on a current security patch level. There is no known mitigation short of patching the binder driver, so prioritize devices that install untrusted apps, where local attackers have an execution foothold. The rooting malware activity in recent headlines is not confirmed in this data to exploit CVE-2020-0041, but patching eliminates the kernel LPE primitive such malware relies on. | 7.8 | 3% | KEV |
| mass≈ billions of Android devices potentially affected (Android's global active install base is on the order of 3 billion devices) | |
| CVE-2020-0069 | Out-of-Bounds Write in MediaTek Command Queue Driver Enables Android Privilege Escalation CVE-2020-0069 is an out-of-bounds write (CWE-787) in the ioctl handlers of the MediaTek Command Queue kernel driver on Android, caused by insufficient input validation and missing SELinux restrictions. Any application running locally can trigger the flaw by sending maliciously crafted ioctl requests, and no special permissions or user interaction are required. A successful exploit corrupts kernel memory and achieves local escalation of privilege, giving the attacker root-level control of the device. Affected users are owners of Android phones built on the multiple MediaTek chipsets named by CISA, spanning Google Android and numerous Huawei/Honor firmware builds (including Honor 20 Pro, Nova 3, Y6 2019, and Berkeley/Columbia/Cornell/Dura firmware variants). The flaw is confirmed as exploited in the wild via CISA's KEV catalog (added 2021-11-03, with ransomware use listed as unknown), EPSS estimates a 1.4% probability of exploitation within 30 days, no public PoC is cataloged, and the KEV listing coincided with reports of rooting malware such as AbstractEmu capable of gaining root on Android devices. Do: Apply the latest vendor firmware / Android security update per vendor instructions, as required by the CISA KEV entry, and verify the device shows a current Android security patch level in Settings > About phone. Because exploitation requires a locally installed app, avoid installing untrusted or sideloaded apps on unpatched MediaTek-based devices as an interim mitigation. Organizations should inventory MediaTek-powered handsets, including the listed Huawei/Honor models, and prioritize patching them given confirmed in-the-wild exploitation. | 7.8 | 1% | KEV |
| mass≈100M+ devices (order of magnitude: hundreds of millions of MediaTek-based Android handsets; exact count unknown) |
Full article406 words · extracted from thehackernews.com · click to collapse
Ravie LakshmananOct 29, 2021
An unidentified threat actor has been linked to a new Android malware strain that features the ability to root smartphones and take complete control over infected smartphones while simultaneously taking steps to evade detection.
The malware has been named "AbstractEmu" owing to its use of code abstraction and anti-emulation checks undertaken to thwart analysis right from the moment the apps are opened. Notably, the global mobile campaign is engineered to target and infect as many devices as possible indiscriminately.
Lookout Threat Labs said it found a total of 19 Android applications that posed as utility apps and system tools like password managers, money managers, app launchers, and data saving apps, seven of which contained the rooting functionality. Only one of the rogue apps, called Lite Launcher, made its way to the official Google Play Store, attracting a total of 10,000 downloads before it was purged.
The apps are said to have been prominently distributed via third-party stores such as the Amazon Appstore and the Samsung Galaxy Store, as well as other lesser-known marketplaces like Aptoide and APKPure.
"While rare, rooting malware is very dangerous. By using the rooting process to gain privileged access to the Android operating system, the threat actor can silently grant themselves dangerous permissions or install additional malware — steps that would normally require user interaction," Lookout researchers said. "Elevated privileges also give the malware access to other apps' sensitive data, something not possible under normal circumstances."
Once installed, the attack chain is designed to leverage one of five exploits for older Android security flaws that would allow it to gain root permissions and take over the device, extract sensitive data, and transmit to a remote attack-controlled server —
- CVE-2015-3636 (PongPongRoot)
- CVE-2015-1805 (iovyroot)
- CVE-2019-2215 (Qu1ckr00t)
- CVE-2020-0041, and
- CVE-2020-0069
Lookout attributed the mass distributed rooting malware campaign to a "well-resourced group with financial motivation," with telemetry data revealing that Android device users in the U.S. were the most impacted. The ultimate objective of the infiltrations remains unclear as yet.
"Rooting Android or jailbreaking iOS devices are still the most invasive ways to fully compromise a mobile device," the researchers said, adding "mobile devices are perfect tools for cyber criminals to exploit, as they have countless functionalities and hold an immense amount of sensitive data."
Found this article interesting? Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post.
Text extracted automatically; images, tables and formatting may be missing. Original: https://thehackernews.com/2021/10/this-new-android-malware-can-gain-root.html