Spyget > Android Malware Uses Blog Posts as C&C | Simply Security

[Simply Security] From our analysis, we found that this malware has two hardcoded C&C servers to which it connects in order to receive commands and to deliver payloads. The first server is just like the usual remote site to which the malware posts information to and gets commands from.

Previous [Previous] Malware Infects U.S. Drone Computer Systems - HotHardware...

Next [Next] Meet Google's Tool for Jettisoning Android Malware, Dubbed...

Some related posts from Technorati and Google.

[Techwatch] Android malware grew by 1410% in first half of 2011 | Techwatch: Trend says that malware targeting Android continues to improve in terms of performance, and it’s getting better at “using new techniques to thwart analysis and to avoid detection.”

[Gregory D. Evans] Android malware uses blog posts as command post « Gregory D ...: The new malware, detected as ANDROIDS_ANSERVER.A, arrives as an e-book reader application and can be downloaded from a third-party Chinese application store.

[SocialTimes.com] Infographic: Global Survey Finds Malware Attacks Up Because of ...: For example, imagine a new link is posted to a popular social network and it directs users to a site that downloads or leads to data-stealing code via obfuscated JavaScript. Organizations need security technology that can analyze links as they appear, because the link path is new and doesn’t have a recognizable signature or known payload.

[mxlab - all about anti virus and anti spam] Malware distribution inspired by Steve Jobs' passing « mxlab – all ...: MX Lab, http://www.mxlab.eu, started to intercept a new malware distribution campaign by email that is inspired on the passing away of Steve Jobs, CEO of Apple, with subjects like: Steve Jobs Not Dead! Steve Jobs: Not Dead Yet! Steve Jobs Alive! Is Steve Jobs Really Dead? The email is send from randomly chosen spoofed address and has the following body: At this URL is a redirect in place that will lead you to the host where the malicious payload is hosted. ...

[Good Filipino] Blog sites used for malware attacks: According to Trend Micro, even the innocent blog sites are now being used as a malware tools to attacks Google Android devices. The security firm recently detected a blog sites with a encrypted content as a command post for malware.

[SecurityWeek RSS Feed] Android Malware Using Blog as C&C Server | SecurityWeek.Com: The malware will connect to the C&C, which replies with a XML file containing the download URL to obtain updated code. Checking the development history on the blog shows that updates focused on creative messages that tricked users into allowing application updates.

[TRANSCEND MEDIA SERVICE] TRANSCEND MEDIA SERVICE » Exclusive: Computer Virus Hits ...: Tadd Sholtis, a spokesman for Air Combat Command, which oversees the drones and all other Air Force tactical aircraft. “We invest a lot in protecting and monitoring our systems to counter threats and ensure security, which includes a comprehensive response to viruses, worms, and other malware we discover.”

[Dvorak News Blog] US Military Drones Compromised by Key-Logger! « Dvorak News Blog: BTW, another reason why I hate this new layout is that if something goes wrong with the post, you could just click back on the browser and all the text was there to change the small problem (like no name or no e-mail) and just click submit comment again.

[Loan toolz] Android Malware Uses Blog Posts as C&C | Loan ToolZ: From our analysis, we found that this malware has two hard-coded C&C Servers to which it connects to receive commands and deliver payloads. The first server is just like the usual remote site, where the malware posts and gets information and commands.

[Paranoid News - UFOs, Conspiracies and the end of the world. Get Paranoid!] SkyNET Is Awke!!: Computer Virus Infects Unmanned Combat ...: every keystroke as they carry out their missions. “Military network security specialists aren't sure whether the virus and its so-called 'keylogger'

[Cisco Blog] Cisco Blog » Blog Archive » Extracting EXE Drop Malware: This is the offset in the data file to the string that is inside the MZ portion of the PE file. Since this is a specific string taken straight from Microsoft’s linker, and the MZ portion of the file has remained the same for years, we can take a static offset from this string to the start of the file.

Reflected tags on Technorati: Blog, ,