Security experts identified a new Android malware family known as DressCode in over 40 Applications in Google Play. It can be used as a proxy to relay attacks in compromised networks and can steal sensitive information from hosts.
The DressCode Android Malware Has a High Infection Rate
Experts from Check Point, a well-known security vendor, have discovered a new Android threat known as DressCode. The malware is found in over 40 applications in the Google Play Store and 400 apps in third-party repositories. The first infections were made in April this year however Google have intervened in the process and have removed the affected applications upon the submitted reports of the vendor.
The Google Play statistics indicate that DressCode has infected between 500 000 and 2 000 000 users. One of the most popular apps that hosted the malware has been downloaded between 100 000 and 500 000 times as per their report.
The DressCode family contains code that hijacks the target devices and connects them to a botnet network. DressCode relies on constant communication with the main command and control (C&C) server of the botnet for commands. The developers of the malware need only to send their malicious instructions to the botnet to have them executed by the victim machines.
The communication itself is carried out via a SOCKS proxy setup that is created upon infection. This allows the botnet operators to control machines behind firewalls and other security counter measures that are widely used by corporate networks and government facilities. Serious damages can be caused if the device is located in a trusted network zone where a lot of devices are connected to the internal network as DressCode can scan all reachable hosts for vulnerabilities and exposed shares. Security experts propose that the most likely scenario is that DressCode exploits the infected devices to perform click-fraud and advertising campaigns for financial gain.
DressCode Distribution Methods
The DressCode Android malware is distributed mainly by infected Google applications and third-party software repositories. Both locations can be risky for the security of the consumers who download untrusted applications.
- Dangers of infected Google Play Store Apps – The Google Play Store, in comparison with other repositories, has an encouraging policy of distributing applications. And while Google employs a variety of security features that scan apps for malware and other types of cyber threats, they still rely on definitions and heuristic scans that may not detect all types of issues. Google Play is noteworthy for hosting a variety of “copy” applications that mimic famous programs in both appearance and functionality but are not developed by the company that they pretend to be. As a result of their use malware can be spread to the victim machine if they interact with a malicious link or feature of the counterfeit program.
- Third Party Stores – They are often used by users looking to expand the traditional catalog of available apps by using these third party repositories. Most of them do not employ strong security checks (or any at all) and are a popular place for hosting illegal content and malware.
Known DressCode Infected Apps
Check Point experts have provided a list of some of the most popular applications infected with the DressCode malware.