Friday, January 31, 2025
HomeMalwareDvmap - First Ever Android Rooting Malware with Code Injection Capabilities

Dvmap – First Ever Android Rooting Malware with Code Injection Capabilities

Published on

SIEM as a Service

Follow Us on Google News

Trojan Dvmap distributed through the Google Play Store, uses various exceptionally dangerous methods, including patching system libraries. It installs malicious modules with different functionality into the system.

Dvmap observed by security experts from Kaspersky Labs in April 2017. To bypass the Google Malware scanner they use to upload a clean Version of the app to store first at the end of March 2017.

Also read Judy malware that Infected Around 8.5 to 36.5 Million Users

Then with updates, they upload malicious app for a short period of time and then revert back to the original one in the same day. They did this no less than 5 times between 18 April and 15 May.

Dvmap is an Extraordinary Malware with a variety of new techniques, more than installing Trojan Libraries it also injects malicious code into runtime libraries(libdmv.so or libandroid_runtime.so).

Dvmap hidden below the app colourblock, downloaded from the Google Play Store for more than 50,000 times and it was reported by Kaspersky Lab to Google and then it has been removed from the play store.

First Ever Android Rooting Malware with Code Injection Capabilities
Image Source: Kaspersky

Attack phase

This trojan also is compatible with both 32 and the 64-bit version of Android. In the initial phase of the attack, trojan tries to install some modules.

Whenever these files effectively obtain root permission, the Trojan will install a few tools into the system. It will likewise install the malicious application “com.qualcmm.timeservices.”

The main purpose of the app com.qualcmm.timeservices is to connect with C&C server
 to download archives and execute the “start” binary from them.

Phase II

Trojan starts Patching either with Game324.res(Android 4.4.4 and older) or Game644.res (Android 5 and later) based on the Android version.

Security Experts said "During the patching process, the Trojan use to overwrite the
current code with the malicious code and put back in the system library.From that
point onward, the Trojan will substitute the original /system/bin/ip with a
malicious one from the archive (Game324.res or Game644.res).

Once Malicious module “ip” file executed by the patched system library. It can switch off “VerifyApps” and empower the installation of applications from 3rd party stores by changing system settings.

Also read Millions of Android Phones suffered with Cloak & Dagger attack

Besides, it can grant the “com.qualcmm.timeservices” application Device Administrator rights without any intercommunication with the client.

Common Defences 

  • To stay secure, use a reputable mobile security solution to detect and remove the threats.
  • Do download apps only from the official market.
  • Before downloading, check for the number of installs, ratings and, most importantly, the content of reviews.
Gurubaran
Gurubaran
Gurubaran is a co-founder of Cyber Security News and GBHackers On Security. He has 10+ years of experience as a Security Consultant, Editor, and Analyst in cybersecurity, technology, and communications.

Latest articles

Hackers Exploiting DNS Poisoning to Compromise Active Directory Environments

A groundbreaking technique for Kerberos relaying over HTTP, leveraging multicast poisoning, has been recently...

New Android Malware Exploiting Wedding Invitations to Steal Victims WhatsApp Messages

Since mid-2024, cybersecurity researchers have been monitoring a sophisticated Android malware campaign dubbed "Tria...

500 Million Proton VPN & Pass Users at Risk Due to Memory Protection Vulnerability

Proton, the globally recognized provider of privacy-focused services such as Proton VPN and Proton...

Arcus Media Ransomware Strikes: Files Locked, Backups Erased, and Remote Access Disabled

The cybersecurity landscape faces increasing challenges as Arcus Media ransomware emerges as a highly...

API Security Webinar

Free Webinar - DevSecOps Hacks

By embedding security into your CI/CD workflows, you can shift left, streamline your DevSecOps processes, and release secure applications faster—all while saving time and resources.

In this webinar, join Phani Deepak Akella ( VP of Marketing ) and Karthik Krishnamoorthy (CTO), Indusface as they explores best practices for integrating application security into your CI/CD workflows using tools like Jenkins and Jira.

Discussion points

Automate security scans as part of the CI/CD pipeline.
Get real-time, actionable insights into vulnerabilities.
Prioritize and track fixes directly in Jira, enhancing collaboration.
Reduce risks and costs by addressing vulnerabilities pre-production.

More like this

New Android Malware Exploiting Wedding Invitations to Steal Victims WhatsApp Messages

Since mid-2024, cybersecurity researchers have been monitoring a sophisticated Android malware campaign dubbed "Tria...

Hackers Impersonate Top Tax Firm with 40,000 Phishing Messages to Steal Credentials

Proofpoint researchers have identified a marked increase in phishing campaigns and malicious domain registrations...

Lazarus Group Drop Malicious NPM Packages in Developers Systems Remotely

In a recent discovery by Socket researchers, a malicious npm package named postcss-optimizer has...