Friday, April 25, 2025
HomeMalwareDvmap - First Ever Android Rooting Malware with Code Injection Capabilities

Dvmap – First Ever Android Rooting Malware with Code Injection Capabilities

Published on

SIEM as a Service

Follow Us on Google News

Trojan Dvmap distributed through the Google Play Store, uses various exceptionally dangerous methods, including patching system libraries. It installs malicious modules with different functionality into the system.

Dvmap observed by security experts from Kaspersky Labs in April 2017. To bypass the Google Malware scanner they use to upload a clean Version of the app to store first at the end of March 2017.

Also read Judy malware that Infected Around 8.5 to 36.5 Million Users

- Advertisement - Google News

Then with updates, they upload malicious app for a short period of time and then revert back to the original one in the same day. They did this no less than 5 times between 18 April and 15 May.

Dvmap is an Extraordinary Malware with a variety of new techniques, more than installing Trojan Libraries it also injects malicious code into runtime libraries(libdmv.so or libandroid_runtime.so).

Dvmap hidden below the app colourblock, downloaded from the Google Play Store for more than 50,000 times and it was reported by Kaspersky Lab to Google and then it has been removed from the play store.

First Ever Android Rooting Malware with Code Injection Capabilities
Image Source: Kaspersky

Attack phase

This trojan also is compatible with both 32 and the 64-bit version of Android. In the initial phase of the attack, trojan tries to install some modules.

Whenever these files effectively obtain root permission, the Trojan will install a few tools into the system. It will likewise install the malicious application “com.qualcmm.timeservices.”

The main purpose of the app com.qualcmm.timeservices is to connect with C&C server
 to download archives and execute the “start” binary from them.

Phase II

Trojan starts Patching either with Game324.res(Android 4.4.4 and older) or Game644.res (Android 5 and later) based on the Android version.

Security Experts said "During the patching process, the Trojan use to overwrite the
current code with the malicious code and put back in the system library.From that
point onward, the Trojan will substitute the original /system/bin/ip with a
malicious one from the archive (Game324.res or Game644.res).

Once Malicious module “ip” file executed by the patched system library. It can switch off “VerifyApps” and empower the installation of applications from 3rd party stores by changing system settings.

Also read Millions of Android Phones suffered with Cloak & Dagger attack

Besides, it can grant the “com.qualcmm.timeservices” application Device Administrator rights without any intercommunication with the client.

Common Defences 

  • To stay secure, use a reputable mobile security solution to detect and remove the threats.
  • Do download apps only from the official market.
  • Before downloading, check for the number of installs, ratings and, most importantly, the content of reviews.
Gurubaran
Gurubaran
Gurubaran is a co-founder of Cyber Security News and GBHackers On Security. He has 10+ years of experience as a Security Consultant, Editor, and Analyst in cybersecurity, technology, and communications.

Latest articles

Microsoft Defender XDR False Positive Leaked Massive 1,700+ Sensitive Documents to Publish

An alarming data leak involving Microsoft Defender XDR has exposed more than 1,700 sensitive...

‘SessionShark’ – A New Toolkit Bypasses Microsoft Office 365 MFA Security

Security researchers have uncovered a new and sophisticated threat to Microsoft Office 365 users:...

Hackers Exploit MS-SQL Servers to Deploy Ammyy Admin for Remote Access

A sophisticated cyberattack campaign has surfaced, targeting poorly managed Microsoft SQL (MS-SQL) servers to...

New Report Reveals How AI is Rapidly Enhancing Phishing Attack Precision

The Zscaler ThreatLabz 2025 Phishing Report unveils the alarming sophistication of modern phishing attacks,...

Resilience at Scale

Why Application Security is Non-Negotiable

The resilience of your digital infrastructure directly impacts your ability to scale. And yet, application security remains a critical weak link for most organizations.

Application Security is no longer just a defensive play—it’s the cornerstone of cyber resilience and sustainable growth. In this webinar, Karthik Krishnamoorthy (CTO of Indusface) and Phani Deepak Akella (VP of Marketing – Indusface), will share how AI-powered application security can help organizations build resilience by

Discussion points


Protecting at internet scale using AI and behavioral-based DDoS & bot mitigation.
Autonomously discovering external assets and remediating vulnerabilities within 72 hours, enabling secure, confident scaling.
Ensuring 100% application availability through platforms architected for failure resilience.
Eliminating silos with real-time correlation between attack surface and active threats for rapid, accurate mitigation

More like this

Russian VPS Servers With RDP and Proxy Servers Enable North Korean Cybercrime Operations

Trend Research has uncovered a sophisticated network of cybercrime operations linked to North Korea,...

New Malware Hijacks Docker Images Using Unique Obfuscation Technique

A recently uncovered malware campaign targeting Docker, one of the most frequently attacked services...

Hackers Deploy New Malware Disguised as Networking Software Updates

A sophisticated backdoor has been uncovered targeting major organizations across Russia, including government bodies,...