Chinese hackers building a botnet out of five million compromised Android devices

RottenSys malware used to create army of bots

botnet

Security researchers have discovered malware that could be assembling a botnet army composed of five million compromised Android devices.

Researchers from cyber security firm Check Point said that the RottenSys malware was targeted at Android users through an app disguised as a WiFi service. It was originally used as malware to serve fraudulent ads on users' displays.

RottenSys has been active since September 2016, amassing approximately 4,964,460 devices by March this year. The top impacted mobile devices brands are Honor, Huawei, and Xiaomi. With its ad serving capabilities, it has been able to make $115,000 in revenues every ten days.

But now evidence has come to light that a new module in the malware is attempting to create a botnet. Researchers said that hackers have been testing a new botnet campaign via the same command and control server since the beginning of February 2018.

"The attackers plan to leverage Tencent's Tinker application virtualization framework as a dropper mechanism. The payload which will be distributed can turn the victim device into a slave in a larger botnet," the researchers said.

"This botnet will have extensive capabilities including silently installing additional apps and UI automation. Interestingly, a part of the controlling mechanism of the botnet is implemented in Lua scripts. Without intervention, the attackers could re-use their existing malware distribution channel and soon grasp control over millions of devices."

According to researchers, the malware may have entered the user's devices before purchase with half of them bought through a Chinese distributor. This suggests that a rogue employee or group may be behind the infection.

Researchers said that users can uninstall the RottenSys dropper if they know the exact package name to remove. At the present time, researchers could not say how the hackers might try to use the botnet they have created.

Featured Resources

Defeating ransomware with unified security from WatchGuard

How SMBs can defend against the onslaught of ransomware attacks

Free download

The IT expert’s guide to AI and content management

How artificial intelligence and machine learning could be critical to your business

Free download

The path to CX excellence

Four stages to thrive in the experience economy

Free download

Becoming an experience-based business

Your blueprint for a strong digital foundation

Free download

Most Popular

What are the pros and cons of AI?
machine learning

What are the pros and cons of AI?

8 Sep 2021
BT conducts 'world's first' trial of quantum-secure communications
Network & Internet

BT conducts 'world's first' trial of quantum-secure communications

13 Sep 2021
Google takes down map showing homes of 111,000 Guntrader customers
data breaches

Google takes down map showing homes of 111,000 Guntrader customers

2 Sep 2021