コンテンツへ移動
Ravington
一覧に戻る
テクノロジー

RedHook Android malware takes over phones via wireless debugging method

Fox News
WhatsApp
RedHook Android malware takes over phones via wireless debugging method
写真: foxnews.com

要点

  • RedHook malware spreads through social engineering tactics, calling under the guise of a banker and having victims install fake applications.
  • It reaches a high privilege level on the device by abusing Android's accessibility and wireless debugging features.
  • Through the application, attackers can monitor the screen, steal passwords, secretly uninstall or install applications.
  • The malware continuously keeps itself active using methods such as playing silent audio and mutual control services.

数字で見る

53 different commands5-minute control alarmAndroid 11

Group-IB security researchers have investigated a new Android malware named RedHook. The attacks begin with individuals acting as bank or government officials calling the user and convincing them to install an application via a fake Google Play Store page. This installed application forces the enabling of Android's Accessibility permission, taking control of the device.

RedHook exploits the Wireless Debugging feature introduced in Android 11 to obtain shell-level privileges. Thanks to this privilege, the malware can execute system commands inaccessible to normal applications, change protected settings, monitor the screen, and record keystrokes. Even though it does not achieve full root access, it can perform serious actions such as disabling the device's security software or installing new malicious applications.

The malware uses highly advanced persistence methods to prevent it from being forcibly removed from the device. It plays silent audio in the background to ensure the operating system considers the process important, and it contains two services that monitor each other to prevent crashing. Experts warn to be cautious of signs such as receiving an urgent call or being asked for accessibility permissions, and advise against installing applications from unauthorized sources.

リアクション

次の記事Apple sues OpenAI over trade secret theft allegations

この記事について質問

回答はこの記事のみからAIが生成します。

よくある質問

How does the RedHook malware infect the device?
Attackers call the user under the name of a bank official or government agency, tricking them into installing an application (APK) via a fake website.
Can this malware provide full control (root) on the device?
No, RedHook does not achieve full root access on the device; however, by using the Wireless Debugging feature, it gains system privileges far beyond those of normal applications.
Why does it become difficult to delete the application after RedHook has infected the device?
Because the malware prevents itself from being shut down by the Android system using CPU wake locks, playing silent audio, and two services that restart each other.

これはAIが生成した短い要約です。全文は出典にあります。

出典で全文を読むfoxnews.comコンテンツの作り方

関連記事