Android Malware Found in Angry Birds Apps

Researchers spotted a number of malicious applications on the Android Market. Photo: Jim Merithew/Wired.com

Google recently removed at least 10 applications from the Android Market, all of which contained malicious code disguised as add-ons to one of the most popular apps of all time.

Each of the removed apps posed as a cheat or an add-on to Angry Birds, the much-lauded mobile application created by Finnish game development studio Rovio.

A number of the apps in question contained a spyware program called Plankton, which connects to a remote server and uploads phone information like the IMEI number, browser bookmarks and browsing history.

“Market descriptions for these apps included the statement ‘brought to you free sponsored by Choopcheec Platform,’” Lookout Security spokesperson Alicia diVittorio told Wired.com in an interview. “[They include] a link to an EULA that does seem to accurately describe the behavior observed to date. We do not see these as desirable behaviors and classify it as Spyware.”

Xuxian Jiang, an assistant professor of computer science at North Carolina State University, initially discovered the malicious applications last week, and reported them to Google on June 5. Google suspended the questionable applications the same day, “pending further investigation.”

Jiang found malicious programs other than Plankton in his research. YZHCSMS, for example, is a Trojan horse virus that jacks up your phone bill by sending large amounts of SMS messages to premium numbers. Jiang says apps containing the virus were available on the Android Market for at least three months before Google pulled them.

Jiang found a similar application, DroidKungFu, circulating Chinese application markets before YZHCSMS made its way to the Android Market. “DroidKungFu can collect various information about the infected phone, including the IMEI number, phone model and Android OS version,” according to a Lookout Security blog post.

For many app developers, the Android Market offers a freedom not found in other application retail outlets. Unlike Apple’s strict application review process, apps submitted to the Android Market are published almost instantaneously. Many appreciate the freedom given to push programs out to the public at such a speed.

However, the Android Market’s app submission process comes at a cost. Google’s lack of vetting applications lends the Market to security vulnerabilities like these. Google mostly relies on a self-policing community — including researchers like Jiang — to spot offending apps, which means malware can sit in the market for months before someone spots it.

With a relatively open submission process like Android’s, this obviously isn’t Google’s first run-in with malicious app removals. Google pulled close to two dozen malware-infected applications in early March, but not before nearly 200,000 downloads occurred.

Going outside of the official Android Market for apps can be even riskier. Because users are able to download applications from alternative app markets (a feature unavailable to iPhone users), many have popped up over the past two years. Without Google’s moderation capabilities in these outside markets, users are more susceptible to downloading malicious apps. A Trojan with “botnet-like capabilities” popped up in early April, for example, highlighting the risk in going to alternative markets for applications.


Android Market web store now checks which apps are compatible with your devices

Google has already made some tough moves to tackle fragmentation, but it’s clearly still wary of the problem. It’s just tweaked the Android Market web store to show users which apps are compatible with which of their gadgets. Of course, compatibility screening was already in place for users who accessed the Market from within their device, but this update should still be of use to those who surf the web store, especially if they’re rocking multiple handsets or a phone-plus-tablet combo.

Android Market web store now checks which apps are compatible with your devices originally appeared on Engadget on Fri, 10 Jun 2011 06:27:00 EDT. Please see our terms for use of feeds.

Permalink Android Central  |   | Email this | Comments

T-mobile, WildTangent to bring 25-cent game rentals to Android devices, harken back to arcade days

Test driving an app isn’t entirely unheard of — Apple introduced its lackluster “Try Before You Buy” system last summer and the Android Market’s got a 15-minute return policy. Now T-Mobile’s teamed up with mobile gaming outfit WildTangent to bring a novel approach to looking under the hood of gaming apps: rentals. The partnership promises to bring 25 cent game rentals to your phone or tablet (considering you’re a T-Mo faithful rocking an Android device), giving you the opportunity to see what a particular game is working with before you commit. The new service also lets users play games for free with advertisements, and applies the cost of rentals to future purchases — rent-to-own style. So it won’t bring the same juvenile thrills as the arcade, but it will let you get your game on at 25 cents a pop. No word yet on when the service will go into effect, so don’t go breaking that piggy bank quite yet.

T-mobile, WildTangent to bring 25-cent game rentals to Android devices, harken back to arcade days originally appeared on Engadget on Thu, 09 Jun 2011 06:43:00 EDT. Please see our terms for use of feeds.

Permalink Electronista  |  sourceWildTangent  | Email this | Comments

More malware in the Android Market: Google removes 26 deleterious app doppelgangers

Ideally, we’d do our smartphone software shopping free from the specter of malicious apps masquerading as useful ones. This past weekend, however, 26 apps in the Android Market were discovered to be packing pernicious code called Droid Dream Light. Apparently, the dastardly devs who made the malware took existing apps and modified them to send details (including IMEI and IMSI info) about the infected handset to a remote server upon receiving a call. The code can also download and cue new package installations, but it needs user approval to do so. Google promptly pulled the offending apps, but their appearance serves as another reminder to be careful when downloading software on your smartphone — prudence demands minding your app permissions, lest your little green bot start stealing your personal info.

More malware in the Android Market: Google removes 26 deleterious app doppelgangers originally appeared on Engadget on Wed, 01 Jun 2011 18:19:00 EDT. Please see our terms for use of feeds.

Permalink The Inquirer  |  sourceThe Lookout Blog  | Email this | Comments

Zinio comes to Android tablets, gives you 24 magazine issues for free


The iPad has yet to transform the publishing world as many expected it would, but some healthy competition from Android tablets should help to keep that process in motion. Zinio‘s reader app is now available on select Android 2.2, 2.3, and all 3.0 tablets, bringing Esquire, National Geographic, and 20,000 other magazine titles to the Motorola Xoom, Samsung Galaxy Tab 10.1, and a half dozen other devices. And, to kick off the launch, Zinio is picking up the tab on the most recent issues of 24 top magazines, as long as you download by June 15. Digital subscriptions are still often more expensive than their print counterparts, but at least Android tablet owners will have a safer place to hide their issues of Playboy.

Continue reading Zinio comes to Android tablets, gives you 24 magazine issues for free

Zinio comes to Android tablets, gives you 24 magazine issues for free originally appeared on Engadget on Tue, 31 May 2011 22:14:00 EDT. Please see our terms for use of feeds.

Permalink   |  sourceZinio  | Email this | Comments

Android Market’s most popular emulators disappear without a trace (update)

If you’re an Android gamer, chances are you’ve heard of Nesoid, Snesoid, Gensoid, N64oid, Ataroid, Gearoid and Gameboid: they’re all video game console emulators developed by yongzh, and many ranked among the most popular paid apps on the Android Market. This week, they’ve got something else in common, too — they’ve all been abruptly removed. Following a complaint from Sega, two emulators were nixed late last month, but we’re hearing that Google has since revoked yongzh’s developer privileges, just like PSX4Droid comrade-in-arms ZodTTD. We’re currently reaching out to both yongzh and Google for comment, and hope to hear back soon, but it’s looking like a bleak week for the emulation community.

Update: We got in touch with yongzh (or Yong Zhang, as he’s known in real life) to discuss the matter, and he confirms that his developer account has been removed and his apps pulled without warning — cutting off his primary source of income and leaving him with an inbox stuffed with worried email from customers. He has, however, already migrated a number of emulators to third-party app store SlideME, where they’ll be free for a while, allowing existing customers to get updates without paying a second time, and likely helping a number of new individuals to mooch off his troubles. He’s not too optimistic about his prospects at SlideME, though.

Android Market’s most popular emulators disappear without a trace (update) originally appeared on Engadget on Sun, 29 May 2011 12:10:00 EDT. Please see our terms for use of feeds.

Permalink   |  sourceyongzh (Android Market)  | Email this | Comments

Lodsys shifts in-app purchasing target to Android devs following Apple response

We figured Apple’s firm response to Lodsys earlier this week regarding its claims against iOS devs would prompt the patent holder to move on to its next target, and sure enough, it looks as if said target has been selected. Unfortunately, a group of Android app devs have now found themselves in the Texas-based company’s crosshairs, which is citing the same patent infringement that Apple recently addressed, relating specifically to in-app upgrade purchases. As was the case with the last round of letters, Lodsys is demanding licensing fees from small, individual developers, who don’t have the resources to fight back. Lodsys appears to be maintaining its trend of ignoring media requests, so we’re keeping an eye on the patent troll’s blog to see if anyone comes up to the surface to defend this latest round of allegations. In the meantime, plugging your ears while humming and ignoring the mailman might not be such a bad idea… you know, if you do this kind of thing for a living.

Lodsys shifts in-app purchasing target to Android devs following Apple response originally appeared on Engadget on Sat, 28 May 2011 14:25:00 EDT. Please see our terms for use of feeds.

Permalink CNET  |  sourceGoogle Groups  | Email this | Comments

Google Maps 5.5 for Android cops more Latitude, tweaks Places and transit pages

Last month we asked for a “funny pages” display in Google’s next release of Maps that shows a thick dotted line depicting where we’ve traveled, but it appears the folks at El Goog had a different agenda in mind for version 5.5. This time around, we see a few redesigns as well as some streamlined Latitude features. First, check-ins and ratings have now been added to the Places page, giving you one extra point of access; you also now have the option of changing your home or work address within your Latitude Location History, in case you ever move or just like to roam from place to place. Last but not least, Google Maps 5.5 for Android also offers reorganized transit station pages that now list off upcoming departures, transit lines serving that particular station, and links to other stops nearby. Though not a substantial upgrade from previous versions, it’s still impressive that Google pushed it out less than a month after 5.4. The new update is available as a free download in the Android Market.

Google Maps 5.5 for Android cops more Latitude, tweaks Places and transit pages originally appeared on Engadget on Fri, 27 May 2011 16:39:00 EDT. Please see our terms for use of feeds.

Permalink   |  sourceGoogle Mobile Blog  | Email this | Comments

Netflix updates Android app, expands device support

Tired of content providers bossing you around, telling you what you can do with your own phone? Good, because Netflix is sick of telling you kids to keep off its lawn. Following a recent update, the outfit’s Android app now officially supports the LG Revolution, Motorola Droid, Casio G’zOne Commando C771, and any unsupported device that just happens to work on its own. In addition to adding official support for the aforementioned trio (and of course, some minor bug fixes), the stream king removed a device check that previously blocked unsupported handsets from attempting playback. Your mileage may vary, but the folks over at Droid Life are reporting success with both the Droid X and Droid X2, as well as the Xperia Play. That’s no guarantee for you and your unsupported device, but at least you have the freedom to fail. That’s nice, isn’t it?

Netflix updates Android app, expands device support originally appeared on Engadget on Thu, 26 May 2011 21:02:00 EDT. Please see our terms for use of feeds.

Permalink Android Central  |  sourceAndroid Market  | Email this | Comments

Madfinger announces new Shadowgun game, with Tegra 2 and Kal-El support

Madfinger Games, the Czech Republic-based company behind Samurai II: Vengeance, has just announced Shadowgun — a futuristic, shoot ’em up game for Tegra 2-equipped Android phones and tablets. Available on both the Tegra Zone app and Android Market, Shadowgun promises to bring console-quality graphics and performance to mobile platforms — presumably with the extra geometric detail and high-res textures we’ve seen in other Tegra 2-tailored games. Madfinger is also developing a version for devices powered by NVIDIA’s forthcoming quad-core processor, alluringly known as Project Kal-El. Price and availability have yet to be announced, but you can find more information in the PR after the break.

Continue reading Madfinger announces new Shadowgun game, with Tegra 2 and Kal-El support

Madfinger announces new Shadowgun game, with Tegra 2 and Kal-El support originally appeared on Engadget on Thu, 26 May 2011 10:22:00 EDT. Please see our terms for use of feeds.

Permalink Droid Life, Android Central  |  sourceMadfinger Games  | Email this | Comments