Scammers make millions in two months with dated Android exploits
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2013-6282 | Improper Input Validation in Linux Kernel on ARM Enables Privilege Escalation CVE-2013-6282 is an improper input validation flaw (CWE-20) in the Linux kernel's get_user and put_user API functions, which on ARM v6k/v7 platforms fail to validate the target address before accessing it. When kernel code uses these functions with an application-supplied pointer, the address is not verified as user space, so a local application can supply a kernel-space address (for example via system calls or ioctls) and read and write kernel memory. An attacker who can already run code on the device can leverage this kernel memory access to escalate privileges to root/kernel level, which can enable persistence or further post-exploitation activity. Affected systems are Linux kernels running on ARM v6k/v7 processors, the architecture that dominated Android smartphones and much embedded Linux hardware in that era; the source data does not enumerate specific affected kernel version ranges. Despite the flaw's 2013 origin, CISA added it to the Known Exploited Vulnerabilities catalog on 2022-09-15, confirming exploitation in the wild, with EPSS estimating a 39.7% probability of exploitation within 30 days (99th percentile). Do: Apply updates per vendor instructions (CISA required action): upgrade the Linux kernel on ARM v6k/v7 devices to a vendor-patched version and install OEM/Google security updates on Android devices, checking vendor advisories for the fixed kernel builds. Inventory legacy and internet-exposed ARM-based embedded systems still running old kernels, and because this is a local privilege escalation, restrict execution of untrusted applications and code on affected devices. | — | 40% | KEV |
| masshundreds of millions of ARM v6k/v7-based devices (legacy Android smartphones and embedded Linux systems) |
Full article712 words · extracted from cyberscoop.com · click to collapse
Get our latest cybersecurity news first on Google.
The malware, called CopyCat, infected 14 million Android devices, rooted 8 million phones and had 3.8 million devices serve ads, according to the Israeli cybersecurity firm Check Point.
A newly discovered strain of Android malware earned hackers $1.5 million, with researchers pointing to a Chinese ad firm as possibly being responsible for the malware’s spread.
The malware, called CopyCat, infected 14 million Android devices, rooted 8 million phones and had 3.8 million devices serve ads, according to the Israeli cybersecurity firm Check Point Technologies. Victims were mainly in South and Southeast Asia, but over 280,000 Android users in the United States were also infected.
India was the hardest hit nation with over 3.8 million victims from the CopyCat campaign.
Researchers from Check Point released a report on the threat on Thursday calling out CopyCat’s “unprecedented success rate.”
CopyCat uses an arsenal of exploits that are, at the most recent, two years old. The oldest exploit, CVE-2013-6282 (VROOT), dates back to 2013. The success of the campaign is a testament to the fact that millions of users are operating old, unpatched and unprotected devices that are indefinitely in danger from attacks that have long since been made public.
This is a problem that hits Android particularly hard because, unlike Apple’s iOS devices, Android’s ecosystem is fragmented in a way that often negatively impacts security.
“CopyCat is a fully developed malware with vast capabilities, including rooting devices, establishing persistency, and injecting code into Zygote — a daemon responsible for launching apps in the Android operating system — that allows the malware to control any activity on the device,” the researchers wrote.

(Check Point)
After infection, the malware roots the victim’s device to gain full control and remove defenses. CopyCat uses Zygote to fraudulently install apps and display ads so it can collect profits estimated by the researchers to reach about $1.5 million during the peak of activity during April and May 2016.
Over $735,000 of the profit came from the 4.9 million app installations. The tactic takes advantage of advertisers paying premiums for ad displays that lead to app installation. CopyCat specifically targets the mobile ad firm Tune.
The campaign has ended due to action by Google, the company said, but infected devices could still be impacted by the malware.
Check Point researchers pointed to MobiSummer, a Chinese ad network, as having “several connections” to the attack’s shared infrastructure, malware code signed by MobiSummer and remote services used by the malware that were created by MobiSummer. Additionally, the malware didn’t target Chinese devices despite over half of the victims residing in Asia.
The company did not respond to a request for comment.
The malware also avoids interfering with major apps like Facebook and WhatsApp for unknown reasons.
Users worried about campaigns should make sure to use devices that have the latest security patches. For many low income Android users around the world, that’s often not an option because cheaper and older Android devices stop receiving security updates long before they go out of use.
Latest Podcasts
Government
FBI officials say AI is bolstering adversaries, emphasizing need to focus on cyber basics, patching
Feds accuse China of ‘systematic’ distillation of U.S. AI models
CIA’s Michael Ellis says cyber intelligence is changing how the agency operates
Jail time for Maine child in 764 marks turning point in federal law enforcement
Technology
Threats
Chinese espionage groups swarm to exploit triple-link chain of zero-days
Microsoft discloses two actively exploited zero-days among 974 vulnerabilities
Russian national extradited to US for alleged involvement in bank-account takeover scheme
Attackers exploit zero-days in consistently besieged SonicWall product
Policy
Whistleblower says USPS deploying new, ‘untested’ IT systems governing mail-in ballots
‘Watershed 250’ test program in Texas looks to private sector for water cybersecurity help
Former sexual abuse victims say Grok used their images, videos to train deepfake capabilities
Cyber threats nudge Trump to sign executive order on foreign equipment in U.S. energy infrastructure
Text extracted automatically; images, tables and formatting may be missing. Original: https://cyberscoop.com/android-malware-copycat-vroot-check-point-mobi-summer/