An Evolution of Android Malware “When stealing data isn’t enough meet…GoManag …“ (Part 2)


by Nathan Collier

In our continued series of how Android malware authors continue adding functionality to their work we take a look at GoManag. First seen last year, targeting Chinese speakers, GoManag is a Trojan that installs as a service so it can run in the background, collects device information and downloads payloads.  Its odd name comes from part of a URL it attempts to contact to.

Malicious GoManag app running in the background as the name “Google Search (Enhanced)”

The first variant contained the following permissions:

ACCESS_NETWORK_STATE

INTERNET

WAKE_LOCK

READ_SMS

WRITE_EXTERNAL_STORAGE

READ_PHONE_STATE

It has functionality to do the following things in the background:

-read text messages

– Uninstall security app 360Safe

-Get phone information

– Download and install APKs

The newer variant contains the same permissions as the first, but with these added permissions:

ACCESS_WIFI_STATE

CHANGE_WIFI_STATE

RECEIVE_SMS

SEND_SMS

WRITE_APN_SETTINGS

WRITE_SMS

The new variant does adds to the existing functionality of the previous version:

– Send SMS

– Collects sent SMS Addresses

– Blacklist Numbers

– Delete Addresses

– Uninstall APKs

In just a couple of months the capabilities of this spyware has grown quite a bit.  Something like this is hard to spot running on your Android device.  Would you think something called “Google Search (Enhanced)” would be malicious?  This is where it’s important to have Webroot SecureAnywhere installed on your Android device to be able detect this well hidden spyware and other malicious apps like it.

If you’re attending the RSA conference this week in San Francisco and want to know more about the process behind Andorid malware stop by room 104 at 10:40 a.m. on day 4 of the conference (Thursday, March 1st) to see Senior Threat Research Analyst Armando Orozco and Webroot’s Manager of Threat Research, Grayson Milbourne present “Cracking Open the Phone: An Android Malware Automated Analysis Primer”. Hope to see you there!

3 thoughts on “An Evolution of Android Malware “When stealing data isn’t enough meet…GoManag …“ (Part 2)

  1. This is a big difference to what google were saying at the beginning, they claimed one of the great things about the android system is that as soon as google spotted any malware they would stop it dead, or words to that effect

  2. Pingback: Malware in the phone? Google Search (Enhanced) « Masks of Eris

Join the Conversation

Please log in using one of these methods to post your comment:

WordPress.com Logo

You are commenting using your WordPress.com account. Log Out / Change )

Twitter picture

You are commenting using your Twitter account. Log Out / Change )

Facebook photo

You are commenting using your Facebook account. Log Out / Change )

Google+ photo

You are commenting using your Google+ account. Log Out / Change )

Connecting to %s