DroidDream Turns Into a Nightmare – Google Removes Several Malware Infected Apps from Official Android Market
Google has removed several of the applications from the Android Market and is looking into others that may be infected.
A Reddit user had posted a note earlier today on his discovery saying, “Someone just ripped off 21 popular free apps from the market, injected root exploits into them and republished. 50k-200k downloads combined in 4 days.” He also provided some additional details on his findings:
“Currently there are more than 50 apps that have either been taken down or are being investigated,” according to Dave Marcus, director of security research and communications at McAfee Labs. “What makes this significant is these apps are in the official Android marketplace, not from a third party marketplace. Analysis has shown that these apps can break out of the typical sandbox that most apps reside in, to potentially gain control over the entire device and its data. In terms of attacks and malware, it doesn’t get any worse than root access, which this malware has.”
The folks over at AndroidPolice have published some informative posts here and here.
Mobile Security Firm Lookout has provided a list of apps that may be affected.