Warning out vs 'Google++' malware — Trend Micro
Google+ members using smartphones running Android 2.2 and lower, look out for that extra plus: a malware that eavesdrops on users' phone calls is using Google's social network Google+ as a cover. But computer security firm Trend Micro noted the malware, which uses the Google+ icon to hide itself from the user, is installed as "Google++." "This malware uses the guise of Google+, Google’s recently released social network, in trying to hide itself from the user. All the above-mentioned services use the Google+ icon, and the app itself is installed under the name Google++," Trend Micro threats analyst Mark Balanza said in a blog post (http://blog.trendmicro.com/android-malware-eavesdrops-on-users-uses-google-as-disguise/). Balanza said the malware, detected as ANDROID_NICKISPY.C, is similar to earlier malware ANDROIDOS_NICKISPY.A and ANDROIDOS_NICKISPY.B, which record phone calls made from an infected device and send it to a remote site. He said the newest malware uses the following services:
- MainService AlarmService SocketService GpsService CallRecordService CallLogService UploadService SmsService ContactService SmsControllerService CommandExecutorService RegisterService CallsListenerService KeyguardLockService ScreenService ManualLocalService SyncContactService LocationService EnvRecordService
- The call must be from the number on the “controller" tag from its configuration file.
- The phone screen must be turned off.