Google's DroidDream cleanup: FAQ

What users of mobile Android devices should know about the infected apps, Google's clean-up effort, and what happens next.

By Ian Paul, PC World |  Mobile & Wireless, Android, Android Market Add a new comment

Google recently began remote wiping Android devices infected with malware after discovering more than 50 malicious applications in the official Android Market.

[ See also: After attacks, Google vows to fortify Android Market ]

Called DroidDream the malware gained root access to devices running Android 2.2.1 (Froyo) and older to access sensitive information such as a device's unique identifying numbers--International Mobile Subscriber Identity (IMSI) and International Mobile Equipment Identity (IMEI)-- as well as the device's language, phone model and, in some cases, UserID.

If something has root access to your device, it means the software could potentially take control of the entire device and any data stored on it.

Mobile security firm Lookout isn't sure what DroidDream was designed to do once it gained access to your phone, but the company said the possibilities were "limitless." DroidDream had been discovered in third-party app stores before, but this was the first time it had popped up in the official Android Market.

With Google starting to remove the malware from infected devices and promising to beef up security for the Android Market, it appears the DroidDream threat will be limited. Nevertheless, if you've got an Android device and are worried you might be infected, here's what you need to know.

Which applications were loaded with DroidDream?

The more than 50 malware-laden apps in the Android Market included software created by three developers: Kingmall2010, we20090202, and Myournet. Malicious titles included Super Guitar Solo, Hot Sexy Videos, Super Stopwatch & Timer, Bubble Shoot, and Quick Delete Contacts. You can find a complete list of infected apps on Lookout's blog.

Have the malicious apps been removed from the Android Market?

Google said late Tuesday that all DroidDream-infected apps were removed from the Market.

I am infected. When can I expect Google to wipe the apps?

Google said anyone with an infected device could expect to hear from android-market-support@google.com by the evening of Tuesday, March 8. The search giant will also install a new security update on your device called "Android Market Security Tool March 2011." The update will automatically undo the exploit.

Wait a second -- Google can remotely wipe data from my device?

Yes, and it's not the first time the company has done this. In June, the company wiped two applications from user's phones that were built by a security researcher. Google said it removed the apps, because the apps "intentionally misrepresented their purpose in order to encourage user downloads."

Google says its ability to remote wipe devices is "one of many security controls the Android team can use to help protect users from malicious applications."

What could attackers do with an infected phone?

It's not clear what the DroidDream attackers planned to do with the infected phones, but with root access the attackers could have downloaded more malicious software to your handset or attempted to pull more personal data from your device.

What exactly did DroidDream do?

DroidDream was embedded within more than 50 Android apps, and would gain root access to your Android device after you ran the app for the first time. It would then install a second application, which required special permission to uninstall. After that, an exploited phone could have more malicious apps installed on it and send more of your data to the DroidDream attackers.


Originally published on PC World |  Click here to read the original story.

ITworld LIVE

Mobile & WirelessWhite Papers & Webcasts

White Paper

Empowering Your Mobile Worker

Today's most productive employees are mobile, and your company's IT strategy must be ready to support them with 24/7 access to the business information they need across a range of mobile devices.See how corporations are meeting the many needs of their mobile workers with the help of Box.

White Paper

Converged Infrastructure for Dummies

As you know, everything is mobile, connected, interactive, and immediate. This is exactly why organizations need a highly agile IT infrastructure in order to keep pace with extreme fluctuations in business demand. This book will help you understand why infrastructure convergence has been widely accepted as the optimal approach for simplifying and accelerating your IT to deliver services at the speed of business while also shifting significantly more IT resources from operations to innovation.Intel and the Intel logo are trademarks of Intel Corporation in the U.S. and/or other countries.

White Paper

SMB's and the Consumerization of IT

As social media becomes an integral part of consumer technology, an increasing number of employees are bringing their personal mobile devices to work, enabling social media and collaboration in the workplace.

White Paper

Refreshing the Mobile Infrastructure

The convenient portability and high functionality of consumer devices combined with the ability to connect to the Internet almost anywhere and at any time are resulting in a growing mobile workforce realizing important productivity benefits - right at the point of contact with customers and partners.

Webcast On Demand

Mobility KnowledgeVault

How "mobile ready" is your infrastructure? This Mobility Knowledge Vault provides a wide variety of expert advice on how to strike a balance between end user ease-of-use and security. Prepare your organization with primers on data encryption and user authentication, device disablement and devising an employee-liable device strategy that makes both IT and users happy.

Sponsor: Dell

See more White Papers | Webcasts

Ask a question

Ask a Question