Chinese hackers building a botnet out of five million compromised Android devices

RottenSys malware used to create army of bots

botnet

Security researchers have discovered malware that could be assembling a botnet army composed of five million compromised Android devices.

Researchers from cyber security firm Check Point said that the RottenSys malware was targeted at Android users through an app disguised as a WiFi service. It was originally used as malware to serve fraudulent ads on users' displays.

RottenSys has been active since September 2016, amassing approximately 4,964,460 devices by March this year. The top impacted mobile devices brands are Honor, Huawei, and Xiaomi. With its ad serving capabilities, it has been able to make $115,000 in revenues every ten days.

But now evidence has come to light that a new module in the malware is attempting to create a botnet. Researchers said that hackers have been testing a new botnet campaign via the same command and control server since the beginning of February 2018.

"The attackers plan to leverage Tencent's Tinker application virtualization framework as a dropper mechanism. The payload which will be distributed can turn the victim device into a slave in a larger botnet," the researchers said.

"This botnet will have extensive capabilities including silently installing additional apps and UI automation. Interestingly, a part of the controlling mechanism of the botnet is implemented in Lua scripts. Without intervention, the attackers could re-use their existing malware distribution channel and soon grasp control over millions of devices."

According to researchers, the malware may have entered the user's devices before purchase with half of them bought through a Chinese distributor. This suggests that a rogue employee or group may be behind the infection.

Researchers said that users can uninstall the RottenSys dropper if they know the exact package name to remove. At the present time, researchers could not say how the hackers might try to use the botnet they have created.

Featured Resources

Four cyber security essentials that your board of directors wants to know

The insights to help you deliver what they need

Download now

Data: A resource much too valuable to leave unprotected

Protect your data to protect your company

Download now

Improving cyber security for remote working

13 recommendations for security from any location

Download now

Why CEOS should care about the move to SAP S/4HANA

And how they can accelerate business value

Download now

Most Popular

Cisco acquires container security startup Banzai Cloud
Security

Cisco acquires container security startup Banzai Cloud

18 Nov 2020
macOS Big Sur is bricking some older MacBooks
operating systems

macOS Big Sur is bricking some older MacBooks

16 Nov 2020
46 million Animal Jam accounts leaked after comms software breach
Security

46 million Animal Jam accounts leaked after comms software breach

13 Nov 2020