Holiday Gift Guide »

Lookout: Legacy Android malware makes another appearance – LeNa

Categories: Android, Security
Tags:
By: , IntoMobile
Tuesday, October 25th, 2011 at 3:28 AM

Lookout Security identified a new Android Trojan, LeNa, which is said to be an evolution of the Legacy variant discovered earlier this year (also known as DroidKungFu). While previous Legacy variants were spotted only in alternative app markets and forums in China, this one (called LeNa) has also been caught on the Android Market (though the affected apps have been deleted by Google in the meantime).

Here’s how it works (from Lookout’s press release):

Unlike its predecessors, LeNa does not come with an exploit to root the device, rather it requests privileged access on a pre-rooted device. On un-rooted devices, it offers “helpful” instructions on how to root the phone. In some samples, LeNa is re-packaged into apps (a VPN management tool, for instance) that could conceivably require root privileges to function properly. Other samples attempt to convince the user that root access is required to update. Once the user grants LeNa with root privileges, it starts its infection process in the background, while performing the advertised application tasks in the foreground.

Once on a user’s device, the Trojan takes a different tactic than previously seen to infect and launch the malware. LeNa hides itself inside an application that is native to the device (an ELF Binary). This is the first time an Android Trojan has relied fully on a native ELF binary as opposed to a typical VM-based Android application. In essence LeNa trojanizes the phone’s system processes, latching itself onto an application that is native to the device and critical to making the phone function properly.

So how to stay safe? Use common sense – install apps only from trusted sources, check the permissions an app requests, be alert for unusual behavior on your phone, and (optionally) download a mobile security app. And in case you care, you can get the complete technical teardown on LeNa from here.

About The Author

Dusan Belic

Dusan has been using smartphones since their introduction and is now following the latest trends in the industry. The "convergence" is what he's most excited about, and writing about it is the next logical thing to do. He thinks that using a smartphone is what everyone who cares about their time should do. In addition to his interests in mobile phones, Dusan also loves to experiment with the latest web and mobile 2.0 services. The idea of accessing and managing your information from any device no matter where you are simply amazes him. Whether it's an online to-do list, note taking service or a video sharing social network, he's there to try it out. He admits though, he's still searching for the ultimate web-based organizational tool, which "sings" perfectly with the mobile PIM application. Dusan used to run SymbianWatch.com which later became part of IntoMobile. He lives in Serbia, South-East Europe, from where he edits the site on a daily basis.