GingerMaster Is First Malware To Utilize A Root Exploit On Android 2.3

New attack can successfully avoid detection by antivirus programs, university research team says

Dark Reading Staff, Dark Reading

August 21, 2011

2 Min Read
Dark Reading logo in a gray background | Dark Reading

Researchers at North Carolina State this week disclosed details on new malware that they say is the first to exercise a root-level exploit against Android 2.3.

The university research team, in collaboration with NetQin, identified new high-risk malware GingerMaster, which they say is the first Android malware that utilizes a root exploit against Android 2.3 (also known as Gingerbread). GingerMaster takes advantage of the most recent root exploit against Android platform 2.3, which was discovered in April, the team says in a blog.

"As this is the first time such malware has been identified, it is not surprising when our experiments show that it can successfully evade the detection of all tested leading mobile antivirus software," the blog states.

The GingerMaster malware is repackaged into legitimate apps, the researchers say. "Within the repackaged apps, it will register a receiver so that it will be notified when the system finishes booting," the blog says. "Inside the receiver, it will silently launch a service in the background [that can] collect various information, including the device id, phone number, and other [data] and then upload them to a remote server."

After getting root privilege, GingerMaster malware will connect to the remote command-and-control server and wait for instructions, the research team says. "According to our investigation, the GingerMaster malware has the payload to silently download and install the app without users' awareness," the blog states.

"Due to the fact that GingerMaster contains the most recent root exploit, we consider it poses one of the most serious threats to mobile users," the North Carolina State team says. The team recommends "common sense" defenses, such as sticking to known app markets and taking care when giving out access permissions.

Have a comment on this story? Please click "Comment" below. If you'd like to contact Dark Reading's editors directly, send us a message.

About the Author

Dark Reading Staff

Dark Reading

Dark Reading is a leading cybersecurity media site.

Keep up with the latest cybersecurity threats, newly discovered vulnerabilities, data breach information, and emerging trends. Delivered daily or weekly right to your email inbox.

You May Also Like


More Insights