Skip to content

ESET researchers detect a new trick used by malware to slip into the official Android app store

Bratislava – May 22, 2020 – ESET researchers discovered an extremely stealthy – yet surprisingly simple – technique that allowed Android malware to stay under the radar. Analyzing the DEFENSOR ID app that was – at the time – available on the official Android app store, ESET researchers learned the app misused Accessibility Services but required no other suspicious permission nor had any other malicious functionality. 

“The Accessibility Services feature is long known to be the Achilles’ heel of the Android operating system, and security solutions have been tuned to detect various combinations of misuse of this weak spot with other indicators of malicious behavior,” explains Lukáš Štefanko, the ESET malware researcher who conducted the analysis into DEFENSOR ID.  

Faced with malware that displayed no additional functionality nor suspicious permissions on top of Accessibility Services, all known security mechanisms failed to trigger any alarm. As a result, DEFENSOR ID made it onto the Google Play store, stayed there for a few months and was never detected by any security vendor participating in the VirusTotal program.

“This has been a valuable lesson for us. Based on what we’ve learned about DEFENSOR ID, we’ve fine-tuned our detection technologies to also cover malware with such a uniquely low detection cross-section,” says Štefanko.

Apart from being extremely stealthy, DEFENSOR ID is capable of inflicting serious harm on its victims. It belongs to the banking trojans malware category and is exceptionally insidious: once installed, it needs its victim to take only one action to fully unleash its power.  

“Once the user activates Accessibility Services, DEFENSOR ID can pave the way for the attacker to clean out the victim’s bank account or cryptocurrency wallet and take over their email or social media accounts, among other malicious actions,” comments Štefanko.  

Following ESET’s notice, Google removed DEFENSOR ID from the official Android app store.

“We decided to publish the results of our investigation into this malware to help defenders cope with ultra-low cross-section Android malware. The creators of such malware are definitely going to face hardened protections around both Google Play and the users’ devices,” concludes ESET’s Štefanko.  

For more details, read “Insidious Android malware gives up all malicious features but one to gain stealth” on WeLiveSecurity.com. Make sure to follow the ESET Research account on Twitter for the latest news from ESET Research.

 The DEFENSOR ID app on Google Play – Portuguese version (Google Translate: “Your new Defensor app available for: / Physical People / Legal entities / From now on you will have more protection when using your applications, encryption for end-to-end users”)

 

About Version 2 Digital

Version 2 Digital is one of the most dynamic IT companies in Asia. The company distributes a wide range of IT products across various areas including cyber security, cloud, data protection, end points, infrastructures, system monitoring, storage, networking, business productivity and communication products.

Through an extensive network of channels, point of sales, resellers, and partnership companies, Version 2 offers quality products and services which are highly acclaimed in the market. Its customers cover a wide spectrum which include Global 1000 enterprises, regional listed companies, different vertical industries, public utilities, Government, a vast number of successful SMEs, and consumers in various Asian cities.

About ESET
For 30 years, ESET® has been developing industry-leading IT security software and services for businesses and consumers worldwide. With solutions ranging from endpoint security to encryption and two-factor authentication, ESET’s high-performing, easy-to-use products give individuals and businesses the peace of mind to enjoy the full potential of their technology. ESET unobtrusively protects and monitors 24/7, updating defenses in real time to keep users safe and businesses running without interruption. Evolving threats require an evolving IT security company. Backed by R&D facilities worldwide, ESET became the first IT security company to earn 100 Virus Bulletin VB100 awards, identifying every single “in-the-wild” malware without interruption since 2003.

Winnti Group targets video game developers again, ESET researchers uncover

BRATISLAVA, MONTREAL – ESET researchers have discovered a new modular backdoor used by the Winnti Group against several video game companies that develop MMO (massively multiplayer online) games. The malware, named PipeMon by ESET, targeted companies in South Korea and Taiwan. The video games developed by these companies are distributed all around the world, are available on popular gaming platforms, and have thousands of simultaneous players.

In at least one case, the attackers compromised the company’s build orchestration server, allowing them to take control of the victim’s automated build systems. This could have allowed the attackers to trojanize video game executables. “However, we do not have evidence this has occurred,” says Mathieu Tartare, Malware researcher at ESET. In another case, the operators compromised the company’s game servers. With this attack, it would be possible to manipulate in-game currencies for financial gain. ESET contacted the affected companies and provided the necessary information and assistance to remediate the compromise.

“Multiple indicators led us to attribute this campaign to the Winnti Group. Some of the command and control domains used by PipeMon were used by Winnti malware in previous campaigns. Furthermore, in 2019 other Winnti malware was found at some of the same companies that were later discovered to be compromised with PipeMon in 2020,” says Mathieu Tartare, ESET researcher monitoring the Winnti Group. There are other notable similarities that researchers explore in the blogpost.

The new modular backdoor PipeMon is signed with a code-signing certificate likely stolen during a previous campaign and shares similarities with the PortReuse backdoor. “This new implant shows that the attackers are actively developing new tools using multiple open source projects and don’t rely solely on their flagship backdoors, ShadowPad and the Winnti malware,” adds Tartare. ESET was able to trace two different variants of PipeMon.

For more technical details about the latest Winnti backdoor, read the blogpost No ‘Game over’ for the Winnti Group on WeLiveSecurity. Make sure to follow ESET research on Twitter for the latest news from ESET Research.

The Winnti Group, active since at least 2012, is responsible for high-profile supply-chain attacks against the video game and software industries, leading to the distribution of trojanized software (such as CCleanerASUS LiveUpdate and multiple video games) that is used to compromise more victims. Recently, ESET researchers also discovered a campaign of the Winnti Group targeting several Hong Kong universities with ShadowPad and the Winnti malware. More details about the group’s arsenal are explored in a white paper published in October 2019.

 

About Version 2 Digital

Version 2 Digital is one of the most dynamic IT companies in Asia. The company distributes a wide range of IT products across various areas including cyber security, cloud, data protection, end points, infrastructures, system monitoring, storage, networking, business productivity and communication products.

Through an extensive network of channels, point of sales, resellers, and partnership companies, Version 2 offers quality products and services which are highly acclaimed in the market. Its customers cover a wide spectrum which include Global 1000 enterprises, regional listed companies, different vertical industries, public utilities, Government, a vast number of successful SMEs, and consumers in various Asian cities.

About ESET
For 30 years, ESET® has been developing industry-leading IT security software and services for businesses and consumers worldwide. With solutions ranging from endpoint security to encryption and two-factor authentication, ESET’s high-performing, easy-to-use products give individuals and businesses the peace of mind to enjoy the full potential of their technology. ESET unobtrusively protects and monitors 24/7, updating defenses in real time to keep users safe and businesses running without interruption. Evolving threats require an evolving IT security company. Backed by R&D facilities worldwide, ESET became the first IT security company to earn 100 Virus Bulletin VB100 awards, identifying every single “in-the-wild” malware without interruption since 2003.

The Winnti Group, active since at least 2012, is responsible for high-profile supply-chain attacks against the video game and software industries, leading to the distribution of trojanized software (such as CCleanerASUS LiveUpdate and multiple video games) that is used to compromise more victims. Recently, ESET researchers also discovered a campaign of the Winnti Group targeting several Hong Kong universities with ShadowPad and the Winnti malware. More details about the group’s arsenal are explored in a white paper published in October 2019.

 

About Version 2 Digital

Version 2 Digital is one of the most dynamic IT companies in Asia. The company distributes a wide range of IT products across various areas including cyber security, cloud, data protection, end points, infrastructures, system monitoring, storage, networking, business productivity and communication products.

Through an extensive network of channels, point of sales, resellers, and partnership companies, Version 2 offers quality products and services which are highly acclaimed in the market. Its customers cover a wide spectrum which include Global 1000 enterprises, regional listed companies, different vertical industries, public utilities, Government, a vast number of successful SMEs, and consumers in various Asian cities.

About ESET
For 30 years, ESET® has been developing industry-leading IT security software and services for businesses and consumers worldwide. With solutions ranging from endpoint security to encryption and two-factor authentication, ESET’s high-performing, easy-to-use products give individuals and businesses the peace of mind to enjoy the full potential of their technology. ESET unobtrusively protects and monitors 24/7, updating defenses in real time to keep users safe and businesses running without interruption. Evolving threats require an evolving IT security company. Backed by R&D facilities worldwide, ESET became the first IT security company to earn 100 Virus Bulletin VB100 awards, identifying every single “in-the-wild” malware without interruption since 2003.

ESET included as Enterprise Architecture EDR solution in Now Tech report

BRATISLAVA – Global cybersecurity leader ESET has been included among 29 vendors in Forrester’s Now Tech: Enterprise Detection and Response Q1 2020 report. The report provides an overview of the technology players in the EDR market and offers insights into understanding their capabilities. Security and risk professionals can use the report to determine the value they can expect from an enterprise detection and response provider and to select one based on size and functionality. Especially in these challenging times, detection & response capabilities are necessary to ensure business continuity.

ESET has been included in the report as an Enterprise Architecture EDR solution, as classified by the architectural decisions behind the product that are designed to provide sub-second behavioral detection and response on the endpoint itself, improving endpoint protection capabilities and offline protection.

Key takeaways from the report include:

  • A key benefit of EDR products is the ability to hunt for indications that an adversary has eluded your security controls and is lying in the weeds of your infrastructure.
  • Each provider in this market has a unique industry focus, geographic footprint, and a set of core competencies, leading to different engagement models that suit a variety of customer needs.

Juraj Malcho, chief technology officer at ESET, commented, “We are proud to be included in the Forrester Now Tech report, and to be recognized among players in the EDR market as, in our opinion, protecting our users and their businesses against the latest advanced persistent threats is central to our mission as a business. Ensuring your business is equipped with capable and cutting-edge detection and response tools is an absolute necessity during these unpredicted times, and we hope that security and risk professionals will be able to make the best decision for their business with ESET’s innovative EDR offerings.”

To read more about Forrester Now Tech, please click here, and to read more about ESET’s enterprise solutions, please click here.

 

About Version 2 Digital

Version 2 Digital is one of the most dynamic IT companies in Asia. The company distributes a wide range of IT products across various areas including cyber security, cloud, data protection, end points, infrastructures, system monitoring, storage, networking, business productivity and communication products.

Through an extensive network of channels, point of sales, resellers, and partnership companies, Version 2 offers quality products and services which are highly acclaimed in the market. Its customers cover a wide spectrum which include Global 1000 enterprises, regional listed companies, different vertical industries, public utilities, Government, a vast number of successful SMEs, and consumers in various Asian cities.

About ESET
For 30 years, ESET® has been developing industry-leading IT security software and services for businesses and consumers worldwide. With solutions ranging from endpoint security to encryption and two-factor authentication, ESET’s high-performing, easy-to-use products give individuals and businesses the peace of mind to enjoy the full potential of their technology. ESET unobtrusively protects and monitors 24/7, updating defenses in real time to keep users safe and businesses running without interruption. Evolving threats require an evolving IT security company. Backed by R&D facilities worldwide, ESET became the first IT security company to earn 100 Virus Bulletin VB100 awards, identifying every single “in-the-wild” malware without interruption since 2003.

訊連科技FaceMe® AI臉部辨識引擎獲日本NEC個人電腦公司採用 打造具備臉部辨識功能之All-in-One個人電腦

202004月21日,台北訊】多媒體領導廠商訊連科技(5203.TW)宣布,旗下FaceMe® AI臉部辨識引擎獲日本NEC個人電腦公司(NEC パーソナルコンピュータ社)採用導入於LAVIE Home All-in-One個人電腦之「LAVIE 人工智慧助手」軟體,透過FaceMe®臉部辨識辨別使用電腦之家庭成員及啟動專屬之使用介面及常用軟體。

LAVIE Home All-in-One為日本NEC個人電腦公司於日本市場上市之全新系列,搭載第 10 代 Intel® Core™處理器,並預載日本NEC個人電腦公司開發之「LAVIE 人工智慧助手」軟體。透過「LAVIE 人工智慧助手」,家庭成員可註冊臉部資訊及設定常用之應用程式,於使用LAVIE Home All-in-One時,透過臉部進行登入、並啟動該成員專屬之 “ Hey LAVIE常見應用”。

「臉部辨識技術是近年來熱門技術,除了各式IoT/AIoT應用外,臉部辨識也可大幅提升消費性電子的方便性。」訊連科技黃肇雄執行長表示:「日本NEC個人電腦公司與訊連在消費性多媒體軟體有長期的合作關係。透過導入FaceMe®臉部辨識,NEC LAVIE Home All-in-one及LAVIE 人工智慧助手可提供家用用戶更方便、快速,且安全性高的臉部辨識。」

FaceMe®為專為邊緣運算(Edge Computing)打造的臉部辨識引擎,可支援Windows、Linux、Android和iOS等多種作業系統。FaceMe®AI臉部辨識引擎,擁有高達99.70%的辨識率,在全球知名NIST臉部辨識競賽中,名列全球最精準且最快速的刷臉技術之一,也是台灣於該項臉部辨識競賽中表現最佳之廠商。除了可以支援功效強大的工作站或個人電腦,亦可針對IoT/AIoT物聯網設備中的輕量、低功耗設備進行優化。彈性SDK解決方案,能建構智慧安控、智慧零售、智慧辦公室、智慧警政和智慧金融等應用。已被國內外多家知名廠商採用,發展以臉部辨識技術為核心之新一代智慧應用。

 

關於訊連科技

訊連科技(5203.TW)創立於1996年,為全球首屈一指的多媒體影音軟體及服務,以及AI臉部辨識技術開發商。訊連科技的產品及服務涵蓋數位內容創作、多媒體影音播放、視訊會議及直播與遠距教學、行動應用、AI人臉辨識等多樣化解決方案,滿足消費性、商務、教育等跨領域多媒體應用。旗下威力導演、相片大師、PowerDVD等電腦軟體和行動APP,透過零售、訂閱式服務及預載等方式,提供個人電腦品牌多樣化應用軟體,於全球累積了超過3億名用戶。

訊連科技亦深耕人工智慧及臉部辨識領域,透過深度學習法開發FaceMe® AI臉部辨識引擎,提供智慧零售、智慧門禁、智慧城市、智慧家庭等垂直應用市場可靠、準確之AIoT人臉辨識解決方案。

 

關於Version 2

Version 2 Digital 是立足亞洲的增值代理商及IT開發者。公司在網絡安全、雲端、數據保護、終端設備、基礎設施、系統監控、存儲、網絡管理、商業生產力和通信產品等各個領域代理發展各種 IT 產品。透過公司龐大的網絡、通路、銷售點、分銷商及合作夥伴,Version 2 提供廣被市場讚賞的產品及服務。Version 2 的銷售網絡包括台灣、香港、澳門、中國大陸、新加坡、馬來西亞等各亞太地區,客戶來自各行各業,包括全球 1000 大跨國企業、上市公司、公用事業、醫療、金融、教育機構、政府部門、無數成功的中小企及來自亞洲各城市的消費市場客戶。

關於CyberLink
訊連科技創立於1996年,擁有頂尖視訊與音訊技術的影音軟體公司,專精於數位影音軟體及多媒體串流應用解決方案產品研發,並以「抓準技術板塊,擴大全球行銷布局」的策略,深根台灣、佈局全球,展現亮麗的成績。訊連科技以先進的技術提供完美的高解析影音播放效果、以尖端的科技提供完整的高解析度擷取、編輯、製片及燒錄功能且完整支援各種高解析度影片及音訊格式。產品包括:「威力導演」、「PowerDVD」、「威力製片」、「威力酷燒」等。

ESET-funded, Slovak-made diagnostic kit for COVID-19 receives regulatory approval in the Slovak Republic, with 100,000 tests ready for delivery

A new COVID-19 diagnostic kit developed by Slovak scientists is registered by Slovakia’s State Institute for Drug Control (ŠUKL). The first 100,000 tests, donated to the Slovak Republic by the ESET Foundation, are ready to be handed over to state diagnostic laboratories.

BRATISLAVA – Slovak scientists from MultiplexDX, the Biomedical Research Center of the Slovak Academy of Sciences (BMC SAS), the Comenius University Science Park in Bratislava, Lambda Life and ProScience Tech joined forces to develop and register the first Slovak-made diagnostic kit for COVID-19. The ESET Foundation supported the development and production of the kit and donated the first 100,000 tests to the government of the Slovak Republic.

On May 14, the State Institute for Drug Control (ŠUKL) approved the kit, which is called vDetect COVID-19 RT-qPCR. The first 100,000 tests will be delivered to state diagnostic laboratories. “The State Institute for Drug Control dealt with the application for registration of the test as a matter of priority, and the final decision was issued within four working days of receiving the application. With the technical dossier and validation tests meeting the necessary criteria, the registration went smoothly. This is the first registration of an IVD test by the State Institute for Drug Control that was designed, manufactured, and registered in Slovakia,” says the director of ŠUKL, PharmDr. Zuzana Baťová, PhD.

During the process of test validation, Slovak researchers from MultiplexDX came up with a way to increase the test’s sensitivity, which slightly delayed the regulatory submission. “When we performed a forensic analysis, we found that the primers used to confirm the test results according to the Charité protocol were not designed optimally. Therefore, we prepared a new version of primers that increased the sensitivity and, consequently, the accuracy of the test. Then it was necessary to repeat testing and, due to this, the original date of the test’s registration was postponed,” explains Pavol Čekan, PhD, founder of MultiplexDX. The tests underwent validation showing a 100% match with the samples already evaluated.”

Blind validation tests, performed at two independent laboratories on 92 clinical samples, showed identical results in comparison with the reference method, as well as with each other. This demonstrates the high reliability of the test directly on clinical samples,” says RNDr. Boris Klempa, DrSc., from BMC SAV.

The ESET Foundation supported the development of the tests, donating the first 100,000 tests to the state. ESET also covered the financing and coordination of activities related to the test’s production and registration.

“The development of the new diagnostic kit confirms that science in the Slovak Republic is being pursued at a high level and, at the same time, demonstrates the ability for science to bring solutions to societal problems. That’s why we have been supporting science for a long time. ESET’s involvement in the development of the coronavirus diagnostic tests has also been an interesting challenge for us because we have been detecting virtual viruses since our founding as a company,” comments Richard Marko, CEO of ESET.

Throughout the test’s development and validation, the team of RNDr. Tomáš Szemes, PhD from the Charles University Science Park in Prague, also participated: “We worked with the team on optimization and validation, and I was surprised at how quickly and smoothly the process went, including registration.” The final documentation for registration at ŠUKL was prepared by Roman Oravec from the non-profit organization CCCT SK.

The Slovak companies Lambda Life and ProScience Tech were also involved during the entire preparation of the diagnostic kit. “With the cooperation of numerous talented scientists and domestic companies, we not only received approval for the first Slovak-made PCR test for COVID-19, but also developed a top product in difficult conditions, one that will help the country when it needs it most. It was by no means an easy task, and I am happy that it succeeded in the end,” concludes Róbert Mistrík from the Slovak government’s permanent crisis team. 



About Version 2 Digital

Version 2 Digital is one of the most dynamic IT companies in Asia. The company distributes a wide range of IT products across various areas including cyber security, cloud, data protection, end points, infrastructures, system monitoring, storage, networking, business productivity and communication products.

Through an extensive network of channels, point of sales, resellers, and partnership companies, Version 2 offers quality products and services which are highly acclaimed in the market. Its customers cover a wide spectrum which include Global 1000 enterprises, regional listed companies, different vertical industries, public utilities, Government, a vast number of successful SMEs, and consumers in various Asian cities.

About ESET
For 30 years, ESET® has been developing industry-leading IT security software and services for businesses and consumers worldwide. With solutions ranging from endpoint security to encryption and two-factor authentication, ESET’s high-performing, easy-to-use products give individuals and businesses the peace of mind to enjoy the full potential of their technology. ESET unobtrusively protects and monitors 24/7, updating defenses in real time to keep users safe and businesses running without interruption. Evolving threats require an evolving IT security company. Backed by R&D facilities worldwide, ESET became the first IT security company to earn 100 Virus Bulletin VB100 awards, identifying every single “in-the-wild” malware without interruption since 2003.

×

Hello!

Click one of our contacts below to chat on WhatsApp

×