Karamjit Posted November 3, 2015 Share Posted November 3, 2015 Creepy Baidu SDK lets hackers spy on what you doBaidu, a Chinese search engine, is offering an SDK (software development kit), which, according to Trend Micro researchers, includes functionality that can be abused to install backdoors on users' devices.The SDK in question goes under the name of Moplus, and according to recent estimates, it has been included in 14,112 Android applications, of which 4,014 are developed by Baidu itself. Putting all the download figures for these apps together, over 100 million Android users may be in danger.The SDK listens for commands coming via HTTP requestsAccording to Trend Micro, the Moplus SDK automatically launches HTTP server on the user's smartphone, which can work silently, in the phone's background, without the user ever noticing it.This server can be controlled by attackers, who can send it HTTP requests on a particular port, telling it to execute malicious commands. Right now, Trend Micro has detected the SDK using the ports 6259 or 40310.These are a few of the scariest things the Moplus SDK can do:get phone detailssend SMS messagesmake phone callsadd new contactsdownload files on the deviceupload files from the deviceget a list of local appssilently install other apps (if the device is rooted)push Web pagesget phone's geolocation, and more.Since the SDK automatically deploys the Web server when an app that includes the Moplus SDK is started, attackers only need to scan a mobile network for the two ports and find vulnerable devices they can abuse.Trend Micro observed the SDK being used by at least one malware strain in the wild (ANDROIDOS_WORMHOLE.HRXA).Thieving SDKs, a new trend among Chinese companiesBaidu was told of this issue and removed some of the SDK's functionality, but not all. In their most recent update, Baidu eliminated the SDK's ability to download or upload files, scan for local apps, add new contacts, or scan downloaded files. All of the other functionality was left intact.This is not the first malicious SDK we see from a Chinese company, having previously reported on another case that involved the Taomike SDK, which was secretly stealing SMS messages from Android devices and uploading to a server in China.The same functionality was also found in another SDK developed by Youmi, but that incident affected only 256 iOS apps, which Apple eventually banned from the App Store until they would remove the aforementioned SDk's code.From Link to comment Share on other sites More sharing options...
Recommended Posts
Archived
This topic is now archived and is closed to further replies.