McAfee Labs Report Reveals New Mobile Threats

Intel Security recently released its McAfee Labs Threats Report: June 2016. The report explains the dynamics of mobile app collusion, where cybercriminals manipulate two or more apps to orchestrate attacks capable of ex-filtrating user data, inspecting files, sending fake SMS messages, loading additional apps without user consent, and sending user location information to control servers.

McAfee Labs has observed such behavior across more than 5,000 versions of 21 apps designed to provide useful user services such as mobile video streaming, health monitoring, and travel planning.

intel-security-logo-300x150

Widely considered a theoretical threat for many years, colluding mobile apps carry out harmful activity together by leveraging inter-app communication capabilities common to mobile operating systems. These operating systems incorporate many techniques to isolate apps in sandboxes, restrict their capabilities, and control which permissions they have at a fairly granular level.

McAfee Labs has identified three types of threats that can result from mobile app collusion:

  • Information theft: An app with access to sensitive or confidential information willingly or unwillingly collaborates with one or more other apps to send information outside the boundaries of the device
  • Financial theft: An app sends information to another app that can execute financial transactions or make financial API calls to achieve similar objectives
  • Service misuse: One app controls a system service and receives information or commands from one or more other apps to orchestrate a variety of malicious activities.

Vincent Weafer, vice president of Intel Security’s McAfee Labs group, said: “Our goal is to make it increasingly harder for malicious apps to gain a foothold on our personal devices, developing smarter tools and techniques to detect colluding mobile apps.”

 

 

 

Share this post:

Comment what you think!