https://www.theregister.com/2023/05/11/bh_asia_mobile_phones/ # # Sign in / up The Register(r) -- Biting the hand that feeds IT # # # Topics Security Security All SecurityCyber-crimePatchesResearchCSO (X) Off-Prem Off-Prem All Off-PremEdge + IoTChannelPaaS + IaaSSaaS (X) On-Prem On-Prem All On-PremSystemsStorageNetworksHPCPersonal Tech (X) Software Software All SoftwareAI + MLApplicationsDatabasesDevOpsOSesVirtualization (X) Offbeat Offbeat All OffbeatDebatesColumnistsScienceGeek's GuideBOFHLegalBootnotesSite NewsAbout Us (X) Special Features Special Features Spotlight on Databases Defense Tech Week Energy Efficient Datacenters Spotlight on RSA Vendor Voice Vendor Voice Vendor Voice All Vendor VoiceAmazon Web Services (AWS) Business TransformationDDN ElasticGoogle Cloud for StartupsIntel vPro (X) Resources Resources Whitepapers Webinars Newsletters [cybercrime] Cyber-crime 6 comment bubble on white Millions of mobile phones come pre-infected with malware, say researchers 6 comment bubble on white The threat is coming from inside the supply chain icon Laura Dobberstein Thu 11 May 2023 // 17:58 UTC # Black Hat Asia Miscreants have infected millions of Androids worldwide with malicious firmware before the devices even shipped from their factories, according to Trend Micro researchers at Black Hat Asia. This hardware is mainly cheapo Android mobile devices, though smartwatches, TVs, and other things are caught up in it. The gadgets have their manufacturing outsourced to an original equipment manufacturer (OEM). That outsourcing makes it possible for someone in the manufacturing pipeline - such as a firmware supplier - to infect products with malicious code as they ship out, the researchers said. [cybercrime] This has been going on for a while, we think; for example, we wrote about a similar headache in 2017. The Trend Micro folks characterized the threat today as "a growing problem for regular users and enterprises." So, consider this a reminder and a heads-up all in one. One type of plugin, proxy plugins, allow miscreants to rent out devices for up to around five minutes at a time. For example, those renting the control of the device could acquire data on keystrokes, geographical location, IP address and more "What is the easiest way to infect millions of devices?" posed senior Trend Micro researcher Fyodor Yarochkin, speaking alongside colleague Zhengyu Dong at the conference in Singapore. Yarochkin compared infiltrating devices at such an early stage of their life cycle to a tree absorbing liquid: you put the infection at the root, and it gets distributed everywhere, out to every single limb and leaf. [cybercrime] [cybercrime] This insertion of malware began as the price of mobile phone firmware dropped, we're told. Competition between firmware distributors became so furious that eventually the providers could not charge money for their product. "But of course there's no free stuff," said Yarochkin, who explained that, as a result of this cut-throat situation, firmware started to come with an undesirable feature - silent plugins. The team analyzed dozens of firmware images looking for malicious software. They found over 80 different plugins, although many of those were not widely distributed. [cybercrime] The plugins that were the most impactful were those that had a business model built around them, were sold on the underground, and marketed in the open on places like Facebook, blogs, and YouTube. * Google: If your Android app can create accounts, it better be easy to delete them, too * Meta does the 'We found baddies and crushed them' thing again - this time for AI * How much to infect Android phones via Google Play store? How about $20k * Apple, Google propose anti-stalking spec for Bluetooth tracker tags The objective of the malware is to steal info or make money from information collected or delivered. The malware turns the devices into proxies which are used to steal and sell SMS messages, take over social media and online messaging accounts, and used as monetization opportunities via adverts and click fraud. One type of plugin, proxy plugins, allow the criminal to rent out devices for up to around five minutes at a time. For example, those renting the control of the device could acquire data on keystrokes, geographical location, IP address and more. "The user of the proxy will be able to use someone else's phone for a period of 1200 seconds as an exit node," said Yarochkin. He also said the team found a Facebook cookie plugin that was used to harvest activity from the Facebook app. [cybercrime] Through telemetry data, the researchers estimated that at least millions of infected devices exist globally, but are centralized in Southeast Asia and Eastern Europe. A statistic self-reported by the criminals themselves, said the researchers, was around 8.9 million. As for where the threats are coming from, the duo wouldn't say specifically, although the word "China" showed up multiple times in the presentation, including in an origin story related to the development of the dodgy firmware. Yarochkin said the audience should consider where most of the world's OEMs are located and make their own deductions. "Even though we possibly might know the people who build the infrastructure for this business, its difficult to pinpoint how exactly the this infection gets put into this mobile phone because we don't know for sure at what moment it got into the supply chain," said Yarochkin. The team confirmed the malware was found in the phones of at least 10 vendors, but that there was possibly around 40 more affected. For those seeking to avoid infected mobile phones, they could go some way of protecting themselves by going high end. That is to say, you'll find this sort of bad firmware in the cheaper end of the Android ecosystem, and sticking to bigger brands is a good idea though not necessarily a guarantee of safety. "Big brands like Samsung, like Google took care of their supply chain security relatively well, but for threat actors, this is still a very lucrative market," said Yarochkin. (r) Get our Tech Resources # Share Similar topics * Black Hat Asia * Firmware * Malware More like these x Similar topics * Black Hat Asia * Firmware * Malware * Manufacturing * Mobile Narrower topics * Advanced persistent threat * Remote Access Trojan Broader topics * Black Hat * IoT * Operating System Similar topics # Share 6 comment bubble on white COMMENTS Similar topics * Black Hat Asia * Firmware * Malware More like these x Similar topics * Black Hat Asia * Firmware * Malware * Manufacturing * Mobile Narrower topics * Advanced persistent threat * Remote Access Trojan Broader topics * Black Hat * IoT * Operating System TIP US OFF Send us news --------------------------------------------------------------------- Other stories you might like Apple, Google propose anti-stalking spec for Bluetooth tracker tags We moved fast and broke things, people got harassed and murdered, so let's revisit privacy Security2 May 2023 | 20 Russia's APT28 targets Ukraine government with bogus Windows updates Nasty emails designed to infect systems with info-stealing malware Cyber-crime2 May 2023 | 4 Google IO: A deeper dive into the developer day's details WebGPU, Chrome extensions, Android, Dart, Flutter, and more Applications11 May 2023 | 4 Want to put more data in your database engine? Learn how bulk Amazon S3 imports open the floodgates for Amazon DynamoDB Sponsored Feature [cybercrime] Storing the Quran on your phone makes you a terror suspect in China Human Rights Watch details mass surveillance and repression Legal4 May 2023 | 55 How fiends abuse an out-of-date Microsoft Windows driver to infect victims It's like those TV movies where a spy cuts a wire and the whole building's security goes out Research24 Apr 2023 | 16 Spain gets EU cash to test next gen network, and US 'scrum for 6G' already under way How much better do mobile networks really have to be by 2030-ish? Networks26 Apr 2023 | 28 Ericsson braces for 'choppy' year despite meeting Q1 expectations Waning 5G deployments in response to economic uncertainty blamed Networks18 Apr 2023 | Microsoft, Fortra are this fed up with cyber-gangs abusing Cobalt Strike Oh, sure, let's play a game of legal and technical whack-a-mole Cyber-crime10 Apr 2023 | 8 Google: If your Android app can create accounts, it better be easy to delete them, too Awoogah, awooooogah, new policy coming for developers Personal Tech7 Apr 2023 | 14 Vietnam threatens to cut off two million mobile subscribers To scupper scams, account-holders must hand over personal info or else Security3 Apr 2023 | 7 April brings tulips, taxes ... and phisherfolk scammers Tactical#Octopus: Don't let users click on that zip file Research3 Apr 2023 | 6 The Register icon Biting the hand that feeds IT About Us* * Contact us * Advertise with us * Who we are Our Websites* * The Next Platform * DevClass * Blocks and Files Your Privacy* * Cookies Policy * Privacy Policy * T's & C's * Do not sell my personal information Situation Publishing Copyright. All rights reserved (c) 1998-2023 no-js