Excerpted from The Seattle PI
Android has been a target for malware creators for a while. Usually, these cyberscum try to get their evil code onto your smartphone through apps masquerading as something else. They may show up briefly in the Android Market (now known as Google Play) only to be yanked once they are discovered.
But now, for the first time, researchers have spotted Android malware that leaps onto a device on its own via a compromised website. Lookout, which makes smartphone security software, says it’s the first Android Trojan that’s delivered by a so-called drive-by download of a site hosting poisoned code. The malware has been given the name NotCompatible.
From Lookout’s blog:
"In this specific attack, if a user visits a compromised website from an Android device, their web browser will automatically begin downloading an application. This process is commonly referred to as a drive-by download."
When the suspicious application finishes downloading, the device will display a notification prompting the user to click on the notification to install the downloaded app. In order to actually install the app to a device, it must have the “Unknown sources” setting enabled (this feature is commonly referred to as “sideloading”). If the device does not have the unknown sources setting enabled, the installation will be blocked."
What exactly does the software do if you allow its installation? Lookout says it serves as a “relay/proxy” and doesn’t necessarily hurt your device. But it could be used to access private networks. Not good!!!
Smart Android owners should not allow the installation of any software they weren’t expecting. It may not be a bad idea to install an antimalware app on your Android device. This may be a first, but it certainly won’t be the last Malware Trojan.
If you have any system questions or concerns on this topic, contact the CCS Retail Systems Support Department at 800.672.4806 or email us
-Bryan
