Chinese hackers building a botnet out of five million compromised Android devices

RottenSys malware used to create army of bots

botnet

Security researchers have discovered malware that could be assembling a botnet army composed of five million compromised Android devices.

Researchers from cyber security firm Check Point said that the RottenSys malware was targeted at Android users through an app disguised as a WiFi service. It was originally used as malware to serve fraudulent ads on users' displays.

RottenSys has been active since September 2016, amassing approximately 4,964,460 devices by March this year. The top impacted mobile devices brands are Honor, Huawei, and Xiaomi. With its ad serving capabilities, it has been able to make $115,000 in revenues every ten days.

But now evidence has come to light that a new module in the malware is attempting to create a botnet. Researchers said that hackers have been testing a new botnet campaign via the same command and control server since the beginning of February 2018.

"The attackers plan to leverage Tencent's Tinker application virtualization framework as a dropper mechanism. The payload which will be distributed can turn the victim device into a slave in a larger botnet," the researchers said.

"This botnet will have extensive capabilities including silently installing additional apps and UI automation. Interestingly, a part of the controlling mechanism of the botnet is implemented in Lua scripts. Without intervention, the attackers could re-use their existing malware distribution channel and soon grasp control over millions of devices."

According to researchers, the malware may have entered the user's devices before purchase with half of them bought through a Chinese distributor. This suggests that a rogue employee or group may be behind the infection.

Researchers said that users can uninstall the RottenSys dropper if they know the exact package name to remove. At the present time, researchers could not say how the hackers might try to use the botnet they have created.

Featured Resources

Navigating the new normal: A fast guide to remote working

A smooth transition will support operations for years to come

Download now

Leading the data race

The trends driving the future of data science

Download now

How to create 1:1 customer experiences at scale

Meet the technology capable of delivering the personalisation your customers crave

Download now

How to achieve daily SAP releases

Accelerate the pace of SAP change to support your digital strategy

Download now

Most Popular

16 ways to speed up your laptop
Laptops

16 ways to speed up your laptop

16 Sep 2020
16 ways to speed up your laptop
Laptops

16 ways to speed up your laptop

16 Sep 2020
Windows Server flaw sparks emergency US gov warning
vulnerability

Windows Server flaw sparks emergency US gov warning

21 Sep 2020