Categories: Malware

Dvmap – First Ever Android Rooting Malware with Code Injection Capabilities

Trojan Dvmap distributed through the Google Play Store, uses various exceptionally dangerous methods, including patching system libraries. It installs malicious modules with different functionality into the system.

Dvmap observed by security experts from Kaspersky Labs in April 2017. To bypass the Google Malware scanner they use to upload a clean Version of the app to store first at the end of March 2017.

Also read Judy malware that Infected Around 8.5 to 36.5 Million Users

Then with updates, they upload malicious app for a short period of time and then revert back to the original one in the same day. They did this no less than 5 times between 18 April and 15 May.

Dvmap is an Extraordinary Malware with a variety of new techniques, more than installing Trojan Libraries it also injects malicious code into runtime libraries(libdmv.so or libandroid_runtime.so).

Dvmap hidden below the app colourblock, downloaded from the Google Play Store for more than 50,000 times and it was reported by Kaspersky Lab to Google and then it has been removed from the play store.

Image Source: Kaspersky

Attack phase

This trojan also is compatible with both 32 and the 64-bit version of Android. In the initial phase of the attack, trojan tries to install some modules.

Whenever these files effectively obtain root permission, the Trojan will install a few tools into the system. It will likewise install the malicious application “com.qualcmm.timeservices.”

The main purpose of the app com.qualcmm.timeservices is to connect with C&C server
 to download archives and execute the “start” binary from them.

Phase II

Trojan starts Patching either with Game324.res(Android 4.4.4 and older) or Game644.res (Android 5 and later) based on the Android version.

Security Experts said "During the patching process, the Trojan use to overwrite the
current code with the malicious code and put back in the system library.From that
point onward, the Trojan will substitute the original /system/bin/ip with a
malicious one from the archive (Game324.res or Game644.res).

Once Malicious module “ip” file executed by the patched system library. It can switch off “VerifyApps” and empower the installation of applications from 3rd party stores by changing system settings.

Also read Millions of Android Phones suffered with Cloak & Dagger attack

Besides, it can grant the “com.qualcmm.timeservices” application Device Administrator rights without any intercommunication with the client.

Common Defences

  • To stay secure, use a reputable mobile security solution to detect and remove the threats.
  • Do download apps only from the official market.
  • Before downloading, check for the number of installs, ratings and, most importantly, the content of reviews.
Gurubaran

Gurubaran is a co-founder of Cyber Security News and GBHackers On Security. He has 10+ years of experience as a Security Consultant, Editor, and Analyst in cybersecurity, technology, and communications.

Recent Posts

Update Alert: Google Warns of Critical Android Vulnerabilities Under Exploit

Google’s March 2025 Android Security Bulletin has unveiled two critical vulnerabilities—CVE-2024-43093 and CVE-2024-50302—currently under limited,…

2 hours ago

BigAnt Server 0-Day Vulnerability Lets Attackers Run Malicious Code Remotely

A critical vulnerability in BigAntSoft's enterprise chat server software has exposed ~50 internet-facing systems to…

2 hours ago

Bubba AI, Inc. is Launching Comp AI to Help 100,000 Startups Get SOC 2 Compliant by 2032.

With the growing importance of security compliance for startups, more companies are seeking to achieve…

4 hours ago

IBM Storage Virtualize Flaws Allow Remote Code Execution

Two critical security flaws in IBM Storage Virtualize products could enable attackers to bypass authentication…

4 hours ago

Progress WhatsUp Gold Path Traversal Vulnerability Exposes Systems to Remote code Execution

A newly disclosed path traversal vulnerability (CVE-2024-4885) in Progress Software’s WhatsUp Gold network monitoring solution…

5 hours ago

CISA Alerts on Active Exploitation of Cisco Small Business Router Flaw

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) issued an urgent warning on March 3,…

6 hours ago