SIGN IN YOUR ACCOUNT TO HAVE ACCESS TO DIFFERENT FEATURES

FORGOT YOUR PASSWORD?

FORGOT YOUR DETAILS?

AAH, WAIT, I REMEMBER NOW!
Need Help? Email [email protected]
  • LOGIN

E-SPIN Group

CONTACT US / GET A QUOTE
  • No products in cart.
  • HOME
  • PROFILE
    • Corporate Profile
    • About us
    • Customer Overview
    • Investor Relations
    • Procurement
  • GLOBAL THEMES
    • Artificial Intelligence (AI)
    • Big Data
    • Blockchain
    • Cloud Computing
    • Cognitive Computing
    • Cyber Security
    • DevSecOps
    • Digital Transformation (DT)
    • Modern Workplace
    • Internet of Things (IoT)
    • Quantum Computing
  • SOLUTIONS
    • Application Security
    • DevSecOps
    • Digital Forensics
    • IT Operations Management (ITOM)
    • Malware Analysis and Reverse Engineering
    • Network Management System (NMS)
    • Network Operation (NetOps)
    • Network Performance Monitoring and Diagnostics (NPMD)
    • Penetration Testing
    • Secure Development
    • Security Information & Event Management (SIEM)
  • INDUSTRIES
    • Aerospace & Defense
    • Automotive
    • Banking & Financial Markets
    • Chemical & Petroleum
    • Commercial and Professional Services
    • Construction & Real Estate
    • Consumer Products
    • Education
    • Electronics
    • Energy & Utilities
    • Food & Beverage
    • Information Technology
    • Insurance
    • Healthcare
    • Goverment
    • Telecommunications
    • Transportation
    • Travel
    • Manufacturing
    • Media & Entertainment
    • Mining & Natural Resources
    • Life Sciences
    • Retail
  • PRODUCTS
    • Brand Overview
      • Acunetix
      • E-Lock
      • Hex-Rays
      • Immunity
      • Progress | Ipswitch
      • Metageek
      • Qualys
      • Parasoft
      • Tenable
      • Titania
      • Veracode
    • Rest of Brands
      • Adobe
      • BeyondTrust
      • Core Security
      • DefenseCode
      • HCL
      • ImmuniWeb
      • LiveAction
      • McAfee
      • Micro Focus
      • Microsoft
        • Microsoft Surface
      • Netsparker
      • Nutanix
      • Paessler
      • PECB
      • Portswigger
      • Red Hat
      • Riverbed
      • RSA
      • Solarwinds
      • TamoSoft
      • Trend Micro
      • TSFactory
      • Trustwave
      • VMware
      • VanDyke
      • Visiwave
    • Services Overview
    • Line Card
  • e-STORE
    • e-STORE
    • eSTORE Guide
    • SUPPORT
  • CAREERS
    • Careers
    • Culture, Values and CSR
    • How We Hire
    • Job Openings
  • BLOG / NEWS
    • Blogs and News
    • Resources Library
    • Calendar of Events
  • CONTACT
  • Home
  • Solution
  • Rise of Joker A new android Malware
Rise of Joker A new android Malware
0
E-SPIN
Thursday, 05 September 2019 / Published in Solution

Rise of Joker A new android Malware

With the Joker (2019) new movie just show in the cinema, we get the news for rise of Joker – a new android malware spread across 472,000 mobile device in total.

It is a new Android Trojan with malware dropper and spyware capabilities,  somehow being downloads as hidden inside mobile application for 427,000 in total across 24 Google Play store.

This new Android Malware, nickname “Joker” is hidden within advertisement frameworks, used by compromised mobile applications, and it design to download additional component to execute more advance capabilities, no just click on hidden advertisement to accumulate revenue from the advertiser, but also harvest mobile application user device information, from contact list, call, credit card information and perform clicks and entering authorization codes for premium service subscriptions without being aware by the mobile applications user. This is doing so by leverage its SMS collection module to sign victims up for premium subscriptions using the authoriztion codes automatically extracted from authorization text messages. In another word, 2 factor authentication (2FA) being compromise under this way for those infected devices.

At the time, only selected countries is targeted, if you download from those countries play store, include but no limited to Australia, France, Germany, India, the UK, and the US. The application send commands and code to be executed via JavaScript-to-Java callbacks on compromised devices, to protect the Trojan being detect from static analysis, a form of mobile application static security testing (Mobile SAST). It further make use of “custom string obfuscation schemes for all the configuration, payload, communication parsing procedures” to make it harder for Mobile SAST to detect it.

Joker being active around early June, but no one know how long it presence during undetected period. Google had proactive removed all Joker-infected applications from the Play Store, but user is advice to check thru your mobile device for any being installed before the action being taken.

A lesson from the case? mobile application being a popular platform for malware to be spread and use to infect millions of mobile device. In particular so hidden inside “free” or “advertisement sponsor” mobile application. Since the user in generic public will download it due to free in nature and already expect to watch advertisement in exchange for the free use of mobile application.

For enterprise customer who had own mobile application use the appstore for distribution, it important to make sure whatever mobile application they intent to upload is perform mobile application security testing (Mobile AST), together with source code static analysis. Most of the time, developer in modern days do not develop everything from sketch, they are buying or make use of “free” component to be use on their own mobile application. Company with the process to monitoring indicator of compromise (IoC) will be important for benchmark and self monitoring for any cyber exposure happen and can taken immediate action.

E-SPIN being active in the cybersecurity testing domain, include mobile application security testing (Mobile AST), static application security testing (SAST), IDE secure code review, software composition analysis (SCA), dynamic application security testing (DAST), or even perform DevSecOps CI/CD integration etc for the partner and customer across the region. Feel free to contact E-SPIN for your project and requirement.

 

 

 

 

 

Tagged under: Anti-Malware, Malware Analysis, Malware Detection

What you can read next

Sentinel HASP HL
FREE Book- E-SPIN Professional Reading on Network, Server and Application Management
FREE Book- E-SPIN Professional Reading on Network, Server and Application Management
Understanding Five Key Challenges Cybersecurity

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Recent Posts

  • Digital transformation accelerated with mobile banking

    While everyone is making use of smartphones, no...
  • DefenseCode Webstrike DAST and Thunderscan SAST Technology Update Training

    For existing and new customers and partners, it...
  • Unlearning is important for adult professional development

    World is changing at the speed of light, at bli...
  • 5 huge benefit of digital transformation

    In search for digital service excellence

    In the 1980s, Tom Peter was published In search...
  • Why paper planner, notebook and journal still one of modern productivity tool

    Paper planner is symbol of dated work practice?...

Recent Comments

  • Dorai M on 5 Common ML Challenges Data Scientists Face

Archives

  • March 2021
  • February 2021
  • January 2021
  • December 2020
  • November 2020
  • October 2020
  • September 2020
  • August 2020
  • July 2020
  • June 2020
  • May 2020
  • April 2020
  • March 2020
  • February 2020
  • January 2020
  • December 2019
  • November 2019
  • October 2019
  • September 2019
  • August 2019
  • July 2019
  • June 2019
  • May 2019
  • April 2019
  • March 2019
  • February 2019
  • January 2019
  • December 2018
  • November 2018
  • October 2018
  • September 2018
  • August 2018
  • July 2018
  • June 2018
  • May 2018
  • April 2018
  • March 2018
  • February 2018
  • January 2018
  • December 2017
  • November 2017
  • October 2017
  • September 2017
  • August 2017
  • July 2017
  • June 2017
  • May 2017
  • March 2017
  • January 2017
  • December 2016
  • November 2016
  • October 2016
  • September 2016
  • August 2016
  • July 2016
  • June 2016
  • May 2016
  • April 2016
  • March 2016
  • February 2016
  • January 2016
  • December 2015
  • November 2015
  • October 2015
  • September 2015
  • August 2015
  • July 2015
  • June 2015
  • January 2015
  • December 2014
  • October 2014
  • September 2014
  • July 2014
  • June 2014
  • May 2014
  • April 2014
  • March 2014
  • February 2014
  • January 2014
  • December 2013
  • November 2013
  • October 2013
  • September 2013
  • July 2013
  • June 2013
  • May 2013
  • April 2013
  • March 2013
  • February 2013
  • January 2013
  • December 2012
  • November 2012
  • October 2012
  • September 2012
  • August 2012
  • July 2012
  • June 2012
  • May 2012
  • February 2012
  • July 2011
  • June 2011
  • February 2009
  • July 2008

Categories

  • Acunetix
  • Adobe
  • Aerospace and Defence
  • AppSec Labs
  • Automotive
  • Banking and Financial Markets
  • BeyondTrust
  • Brand
  • Chemical and petroleum
  • Codified Security
  • Commercial and Professional Services
  • Construction and Real Estate
  • Consumer products
  • Contact Us
  • Core Impact
  • Core Security
  • DefenseCode
  • E-Lock
  • Education
  • Electronics
  • Energy and utilities
  • FAQ
  • Food and Beverage (F&B)
  • GFI
  • Global Themes and Feature Topics
  • Government
  • HCL
  • Healthcare
  • Hex-Rays
  • IBM
  • Immunity
  • ImmuniWeb
  • Industries
  • Information Technology
  • Insurance
  • Ipswitch
  • Job
  • Life Science
  • LiveAction
  • Logpoint
  • Manufacturing
  • McAfee
  • Media and Entertainment
  • Metageek
  • Micro Focus
  • Microsoft
  • Mining and Natural Resources
  • Nessus
  • Netsparker
  • News
  • Nutanix
  • Paessler
  • Parasoft
  • PECB
  • PortSwigger
  • Pradeo
  • Product
  • Qualys
  • Rapid7
  • RedHat
  • Retail
  • Retina
  • Riverbed
  • RSA
  • Security Innovation
  • Security Roots
  • Services
  • SILICA
  • Smart City
  • Soft Activity
  • SolarWinds
  • Solution
  • Symantec
  • TamoSoft
  • Telecommunications
  • Tenable
  • Titania
  • Transportation
  • Travel
  • Trend Micro
  • Trustwave
  • TSFactory
  • Uncategorized
  • Vandyke
  • Veracode
  • Videos
  • VisiWave
  • VMware
  • Webinar Archive

Meta

  • Log in
  • Entries feed
  • Comments feed
  • WordPress.org

CORPORATE

  • Profile
  • About us
  • Careers
  • Investor Relations
  • Procurement

SOLUTIONS & PRODUCTS

  • Industries
  • Solutions
  • Products
  • Brand Overview
  • Services

STORE & SUPPORT

  • Shop
  • Cart
  • Checkout
  • My Account
  • Support

PRODUCTS & SERVICES

  • Industries
  • Solutions
  • Products
  • Brand Overview
  • Services

FOLLOW US

  • Facebook
  • Twitter
  • Pinterest
  • LinkedIn
  • YouTube
  • WordPress Blog
© 2005 - 2021 E-SPIN Group of Companies | All rights reserved.
  • Contact
  • Privacy
  • Terms of use
TOP