Android device shutdown hijacking software appears in China

Android device shutdown hijacking software appears in China

[[127995]]

Antivirus company AVG recently discovered an Android malware called "PowerOffHijack" that works in a unique way: it hijacks the shutdown process. PowerOffHijack makes your phone look like it is turned off, and then snoops on your phone.

In other words, when you press the power off button, your device does not actually shut down. Although you still see the shutdown screen and the screen turns black, your phone or tablet is actually on.

When your Android device is in this state, PowerOffHijack will make phone calls, take photos, and "perform other tasks without the user's knowledge."

Here’s how this Android malware hijacks your computer:

First, it gains root privileges.

Then, after gaining root privileges, the malware injects itself into the system_server process and hijacks the mWindowManagerFuncs object.

Then, when you press the power button, a fake dialog box will appear. If you choose to shut down, it will show a fake shutdown screen with the screen off but the phone on.

Finally, in order to make your phone look like it is really turned off, some system broadcast services are also hijacked.

Here is the code for PowerOffHijack to record the call:

Here is the code that PowerOffHijack uses to send a private message:

While AVG has published numerous reports describing how PowerOffHijack hijacks the shutdown process, there is little information about the software itself. AVG did not explain how they discovered the malware, nor how it got onto Android devices. The fact that the software requires root access means it won't just access your phone while you're browsing the web.

Most Android malware enters Android devices when users install suspicious apps from third-party app stores.

"We found that this malware targets Android systems below 5.0, it requires root privileges, and so far we have found about 10,000 devices infected, mostly in China because it first appeared in China. We see it spreading in the Chinese app market," an AVG spokesperson told reporters.

<<:  Apple releases second beta of iOS 8.3 to developers

>>:  Cortana UI is like this now, why don’t you chat with it?

Recommend

Huang Zhizhong personally taught: "35 Days of Super Persuasion" (Issue 12)

Do you have the following problems on Zhiyang? 01...

The unity of aging and evolution: Why do lifespans vary so much across species?

We can understand aging from an evolutionary pers...

Thanks to the discovery of lithium, you can happily browse your phone every day!

END Tadpole Musical Notation original article, pl...

Which one is more important, conversion or traffic?

Why conversion is more important than traffic Fro...

Driver killed elderly cyclist after looking down at phone 39 times in 7 minutes

On October 24, a bus driver took passengers from ...

Analyze the marketing strategy of maternal and infant brands!

With the implementation of the "Three-Child ...

What is the Northeast Cold Vortex?

"It started snowing again in April", &q...

Lizard Squad: Microsoft and Sony are idiots

[[125262]] For many gamers, this Christmas was a ...

National Hepatitis Day丨How does your liver become overdrawn step by step?

The cover image and the images in this article ar...

Quantum computers: a three-step leap from the laboratory to changing the world

Quantum computers have been one of the hottest st...

How to make a competitive product analysis report?

1. Preliminary preparation: Before making any com...