Welcome, Guest: Register On Nairaland / LOGIN! / Trending / Recent / New
Stats: 3,148,779 members, 7,802,390 topics. Date: Friday, 19 April 2024 at 01:36 PM

TECNO, Gionee, & Fake Galaxy Phones Preloaded With DeathRing Trojan? - Phones - Nairaland

Nairaland Forum / Science/Technology / Phones / TECNO, Gionee, & Fake Galaxy Phones Preloaded With DeathRing Trojan? (24463 Views)

delete this post / Opinions Pls: Which Of These Is The Best.. Tecno, Gionee, Innjoo, Infinix.. / As A Tecno, Gionee User Do U In Anyway Enver Your Samsung, Htc And Xperia Users? (2) (3) (4)

(1) (2) (3) (4) (Reply) (Go Down)

TECNO, Gionee, & Fake Galaxy Phones Preloaded With DeathRing Trojan? by Nobody: 10:28am On Dec 07, 2014
Pre-loaded Malware Found On TECNO Smartphones: The Deathring Trojan
When you walk out of a retailer with a shiny new phone, you trust that it’s clean and safe to use. But this might not always be the case, as evidenced by the latest pre-loaded malware Lookout identified called "DeathRing". DeathRing is a Chinese Trojan that is pre-installed on a number of smartphones most popular in Asian and African countries.

The Trojan masquerades as a ringtone app, but instead can download SMS and WAP content from its command and control server to the victim’s phone. It can then use this content for malicious means. For example, DeathRing might use SMS content to phish victim’s personal information by fake text messages requesting the desired data. It may also use WAP, or browser, content to prompt victims to download further APKs — concerning given that the malware authors could be tricking people into downloading further malware that extends the adversary’s reach into the victim’s device and data.

The malware is activated in two ways — both dependent on the victim’s use of the phone. First, the malware will activate if the phone is powered down and rebooted five times. On the fifth reboot, the malware starts. Second, the malicious service will start after the victim has been away and present at the device at least fifty times.

Counterfeit Samsung GS4/Note II
Various TECNO devices
Gionee Gpad G1
Gionee GN708W
Gionee GN800

Polytron Rocket S2350
Hi-Tech Amaze Tab
Karbonn TA-FONE A34/A37
Jiayu G4S – Galaxy S4 Clone
Haier H7
No manufacturer specified i9502+ Samsung Clone

The main countries of concern are Vietnam, Indonesia, India, Nigeria, Taiwan, and China.

https://blog.lookout.com/blog/2014/12/04/deathring/

4 Likes 1 Share

Re: TECNO, Gionee, & Fake Galaxy Phones Preloaded With DeathRing Trojan? by Nobody: 10:32am On Dec 07, 2014
http://www.csoonline.com/article/2855730/malware-cybercrime/android-deathring-malware-being-preloaded-on-cheap-smartphones.html


For the second time in a year, Chinese-made Android smartphones have been discovered pre-flashed with malware, this time a Trojan security firm Lookout Mobile has ominously dubbed 'DeathRing'.

On infected handsets, DeathRing pretends to be a ringtone app but can be used to download other malware, communicating with its command and control via SMS or even the ancient WAP.

It activates once the device has been rebooted five times or, in other cases, the device has been accessed 50 times by its owner from the homescreen.
[How to spot a phishing email]

By today's ambitious mobile malware standards, DeathRing is pretty low-rent. The list of cheap clone handsets on which is was found - including models from Gionee, Polytron, Karbonn, Hi-Tech, Jiayu, Haier, TECNO, and GPAD - aren't sold to consumers beyond Asia and Africa so the threat is non-existent in the UK and US.

That might also explain the use of WAP, a defunct technology elsewhere. According to Lookout, the countries affected are Vietnam, Indonesia, India, Nigeria, Taiwan, and China.

The wider significance is that the issue of malware loaded on to devices as a part of factory or supply chain firmware flashing seems to be getting slowly worse. Earlier this year, Lookout reported another Trojan called Mouabad which used an identical method to get itself on to factory-fresh handsets.

In a separate attack, security firm Marble Security discovered a fake Russian-made version of Netflix that had been pre-installed on Android devices.

Could higher-end Android handsets be affected by this sort of attack in the near future?

"It's theoretically definitely possible, but for the time being unlikely. This is because many manufacturers of the higher-tier devices generally found in Western countries have more stringent regulation over their supply chains and better quality control programs," said Lookout's Jeremy Linden.

"However, like all malware, where the money is, the malware technology follows. If authors find this distribution method to be lucrative, they may evolve to attack the bigger fish."

For the user, it's not a case of detecting and removing these Trojans. Loaded as part of the firmware image (older versions of Android), they can't be removed manually without re-flashing the operating system.

According to Lookout, detection rates have been in the "tens of thousands" which suggests that an issue only affecting some handsets.

This story, "Android 'DeathRing' malware being pre-loaded on cheap smartphones" was originally published by Techworld.com.

More Supply Chain Woes: DeathRing Is Factory-Loaded Smartphone Malware


The folks over at Lookout Security have an interesting blog piece on “DeathRing,” a Chinese Trojan that comes pre-installed on a number of smartphones most popular in Asian and African countries.

According to the bulletin, the Trojan masquerades as a ringtone app, but downloads an SMS and WAP (or “wireless access protocol” ) content from a command and control server to the victim’s phone once it is installed.

That downloaded content can be used for various malicious, money-making schemes, according to Lookout. For example, DeathRing can use the SMS content to send phishing text messages to the phone to elicit sensitive information from the user. The WAP content to manipulate a mobile user’s web browsing session. For example: the attackers might prompt victims to download additional mobile applications or add-ons, potentially extending their reach over the victim’s device and data.

[Read more Security Ledger coverage of supply chain risks.]

Lookout said that DeathRing has been found only in low numbers and outside of Western markets. Copies of the mobile malware have turned up in Vietnam, Indonesia, India, Nigeria, Taiwan, and China. The malware has been identified running on off-market counterfeit phones posing as Samsung devices including the Galaxy S4, the GS4/Note II and others. Other affected platforms include devices by Gionee (Gpad G1, GN708W, GN800) Polytron Rocket S2350, Hi-Tech Amaze Tab Karbonn TA-FONE A34/A37, the Jiayu G4S (another Galaxy S4 Clone) and the Haier H7.

The pattern and features of DeathRing are similar to another piece of mobile malware that was also linked to corrupted supply chains: Mouabad, which Lookout warned of in April. Like DeathRing, that malware also used premium SMS and asked victims to install added modules that extended the malware’s functionality.

Mobile handset makers are particularly vulnerable to corrupt- or corrupted supply chain partners, given the intense price pressure and the myriad of components that make up even a low-end smart phone.

Legal and information security experts say that attacks that come by way of suppliers and other third-party business partners are one of the biggest threats that modern organizations face. However, few firms prioritize scrutiny of third-party contractors and components.

At an expert panel on supply chain security that met in Boston in November, companies were encouraged to beef up auditing of internal- and partner assets and to seek contractual protections that will indemnify them in the event that a breach at a supplier or business partner exposes data that materially affects their firm.

Read more via The Official Lookout Blog | DeathRing: Pre-loaded malware hits smartphones for the second time in 2014.
Re: TECNO, Gionee, & Fake Galaxy Phones Preloaded With DeathRing Trojan? by sexyedjutto: 10:33am On Dec 07, 2014
Wow....is this first to comment,,,,didnt read d many writups joor
Re: TECNO, Gionee, & Fake Galaxy Phones Preloaded With DeathRing Trojan? by parrotibaba(m): 10:33am On Dec 07, 2014
and u used only tecno to head ur thread why?

4 Likes

Re: TECNO, Gionee, & Fake Galaxy Phones Preloaded With DeathRing Trojan? by Nobody: 10:45am On Dec 07, 2014
mods, FP please

3 Likes

Re: TECNO, Gionee, & Fake Galaxy Phones Preloaded With DeathRing Trojan? by Gmajor(m): 12:49pm On Dec 07, 2014
china will always be china cos its made In china.
Where are the gionee fanboys ?
I hope the have seen that tecno n gionee are all birds of the same feather ?

5 Likes

Re: TECNO, Gionee, & Fake Galaxy Phones Preloaded With DeathRing Trojan? by Collinz2(m): 1:30pm On Dec 07, 2014
I dnt knw wht to say
Re: TECNO, Gionee, & Fake Galaxy Phones Preloaded With DeathRing Trojan? by Nobody: 1:41pm On Dec 07, 2014
Chinko

1 Like

Re: TECNO, Gionee, & Fake Galaxy Phones Preloaded With DeathRing Trojan? by lilmax(m): 1:41pm On Dec 07, 2014
What do you expect?

1 Like 1 Share

Re: TECNO, Gionee, & Fake Galaxy Phones Preloaded With DeathRing Trojan? by Codedboy95(m): 2:09pm On Dec 07, 2014
haaa *throws tecno phone away*.. akoba adaba

8 Likes

Re: TECNO, Gionee, & Fake Galaxy Phones Preloaded With DeathRing Trojan? by treasuress: 3:52pm On Dec 07, 2014
damnnn dis is bad embarassed
Re: TECNO, Gionee, & Fake Galaxy Phones Preloaded With DeathRing Trojan? by Nobody: 3:53pm On Dec 07, 2014
wink
Re: TECNO, Gionee, & Fake Galaxy Phones Preloaded With DeathRing Trojan? by Descartes: 3:53pm On Dec 07, 2014
The fear of market competition by the "Big Boss" in the Smartphone market shocked

Anyway, it seems that everything in Africa/Nigeria is China-fitted tongue

These include: Executive, Legislature, Judiciary etc... lipsrsealed

10 Likes

Re: TECNO, Gionee, & Fake Galaxy Phones Preloaded With DeathRing Trojan? by OCTAVO: 3:54pm On Dec 07, 2014
Re: TECNO, Gionee, & Fake Galaxy Phones Preloaded With DeathRing Trojan? by Nobody: 3:55pm On Dec 07, 2014
ThankGOD say i no dey use these phones o
Re: TECNO, Gionee, & Fake Galaxy Phones Preloaded With DeathRing Trojan? by lawrenceunaa: 3:55pm On Dec 07, 2014
Seems infinix zero would be the next option cry

2 Likes

Re: TECNO, Gionee, & Fake Galaxy Phones Preloaded With DeathRing Trojan? by PrettyHausaGirl(f): 3:56pm On Dec 07, 2014
Thank God for iPhone6
Re: TECNO, Gionee, & Fake Galaxy Phones Preloaded With DeathRing Trojan? by henryobinna(m): 3:56pm On Dec 07, 2014
i knew it
no wonder my tecno dey misbehave.
but na lie oh ;P

2 Likes 1 Share

Re: TECNO, Gionee, & Fake Galaxy Phones Preloaded With DeathRing Trojan? by PERFECT2(m): 3:58pm On Dec 07, 2014
We cant even calm down to digest these our fp stories again due to per minute updates. Pls,mods....this is not a T.V STATION.

10 Likes 2 Shares

Re: TECNO, Gionee, & Fake Galaxy Phones Preloaded With DeathRing Trojan? by CRAZYMADMAN(m): 3:58pm On Dec 07, 2014
make them no vex o, gionee all the way! cool

4 Likes

Re: TECNO, Gionee, & Fake Galaxy Phones Preloaded With DeathRing Trojan? by Nobody: 3:58pm On Dec 07, 2014
Like me if u love blackberry

8 Likes

Re: TECNO, Gionee, & Fake Galaxy Phones Preloaded With DeathRing Trojan? by Nobody: 3:58pm On Dec 07, 2014
Oboi! Even people's nudes shocked
Re: TECNO, Gionee, & Fake Galaxy Phones Preloaded With DeathRing Trojan? by Promking: 3:59pm On Dec 07, 2014
shocked

OP, so if you didnt put tecno in all CAPS, you wont pass ur message

and,
By today's ambitious mobile malware standards, DeathRing is pretty low-rent. The list of cheap clone handsets on which is was found - including models from Gionee, Polytron, Karbonn, Hi-Tech, Jiayu, Haier, TECNO, and GPAD - aren't sold to consumers beyond Asia and Africa so the threat is non-existent in the UK and US.
which day did tecno become a clone device?? undecided

Also
Counterfeit Samsung GS4/Note II
Various TECNO devices
Gionee Gpad G1
Gionee GN708W
Gionee GN800
Polytron Rocket S2350
Hi-Tech Amaze Tab
Karbonn TA-FONE A34/A37
Jiayu G4S – Galaxy S4 Clone
Haier H7
No manufacturer specified i9502+ Samsung Clone
You specified others but could not for tecno.....why the hating nau

finally,
Lookout said that DeathRing has been found only in low numbers and outside of Western markets. Copies of the mobile malware have turned up in Vietnam, Indonesia, India, Nigeria, Taiwan, and China. The malware has been identified running on off-market counterfeit phones posing as Samsung devices including the Galaxy S4, the GS4/Note II and others. Other affected platforms include devices by Gionee (Gpad G1, GN708W, GN800) Polytron Rocket S2350, Hi-Tech Amaze Tab Karbonn TA-FONE A34/A37, the Jiayu G4S (another Galaxy S4 Clone) and the Haier H7.
and you didnt mention any tecno device here angry....shame on you


#teamTecno jaare

15 Likes

Re: TECNO, Gionee, & Fake Galaxy Phones Preloaded With DeathRing Trojan? by flexing11(m): 3:59pm On Dec 07, 2014
buttress pls,am lost,,,,,,,,,
Re: TECNO, Gionee, & Fake Galaxy Phones Preloaded With DeathRing Trojan? by DonaldGenes(m): 3:59pm On Dec 07, 2014
It is true..I am blazing with Team Gionee P2


Some of the reason behind that research by me is that , overtime, Some Apps I downloaded mutates to Android Malware.Hence, I think that's why Google has now come up with a plan that any App to be downloaded from Googleplay has to pass certain test and to be monitored 24hrs

3 Likes

Re: TECNO, Gionee, & Fake Galaxy Phones Preloaded With DeathRing Trojan? by UjSizzle(f): 3:59pm On Dec 07, 2014
Make una leave chinko products alone o undecided

1 Like

Re: TECNO, Gionee, & Fake Galaxy Phones Preloaded With DeathRing Trojan? by jaymejate: 4:00pm On Dec 07, 2014
weytin all dis mean

#confused

3 Likes 1 Share

Re: TECNO, Gionee, & Fake Galaxy Phones Preloaded With DeathRing Trojan? by Funkymallam(m): 4:00pm On Dec 07, 2014
Samsung, I see u. grin grin grin

1 Like

Re: TECNO, Gionee, & Fake Galaxy Phones Preloaded With DeathRing Trojan? by Electronzeez(m): 4:00pm On Dec 07, 2014
Of course only I9500(samsung galaxy s4) is sold to nigeria...anything + is fake and not apparently from samsung especially if the s4 is made from vietnam,china or korea.

I really dont know much about tecno phones model code.
Re: TECNO, Gionee, & Fake Galaxy Phones Preloaded With DeathRing Trojan? by Nobody: 4:00pm On Dec 07, 2014
not surprised sad
Re: TECNO, Gionee, & Fake Galaxy Phones Preloaded With DeathRing Trojan? by Therock5555(m): 4:01pm On Dec 07, 2014
Ok I have rebooted my fone twice, lemme reboot it trice again

I like virus and malware joor

(1) (2) (3) (4) (Reply)

Factory Reset Code For Tecno T9 / Screenshot And Post Your Data Usage In November / Why Size Matters A Lot To Nigerians – @itelmobileng

(Go Up)

Sections: politics (1) business autos (1) jobs (1) career education (1) romance computers phones travel sports fashion health
religion celebs tv-movies music-radio literature webmasters programming techmarket

Links: (1) (2) (3) (4) (5) (6) (7) (8) (9) (10)

Nairaland - Copyright © 2005 - 2024 Oluwaseun Osewa. All rights reserved. See How To Advertise. 44
Disclaimer: Every Nairaland member is solely responsible for anything that he/she posts or uploads on Nairaland.