Most Android threats would be blocked if phones ran latest Android version, report says

Android 4.2 contains protection against premium rate SMS apps, but has a very low distribution rate, Juniper researchers say

Over three quarters of Android threats are malicious apps that send SMS messages to premium rate numbers and could be mitigated by a protection feature present in Android 4.2, according to researchers from networking vendor Juniper Networks.

However, because manufacturers and carriers fail to update Android end user devices in a timely fashion, only 4 percent of devices currently run Android 4.2, even though this version was released more than six months ago.

From March 2012 to March 2013 the number of mobile threats grew by 614 percent to reach a total of 276,259 malicious samples, researchers from Juniper Networks' Mobile Threat Center (MTC) said in a report released Wednesday. Of those malicious applications, 92 percent target the Android operating system, they said.

The surge of Android malware in the past two years is consistent with the findings of other security vendors that track mobile threats. This growth is primarily driven by Android's "commanding share" of the global smartphone market, the Juniper researchers said.

The majority of Android malware, 77 percent, are apps that earn money for their creators by either requiring users to send SMS messages to premium rate numbers or by surreptitiously sending such messages on their own. These threats usually masquerade as legitimate applications or come bundled in pirated apps.

The Juniper researchers estimate that every successful attack using such an app can bring an immediate profit of US$10 for the attacker on average.

Android 4.2 introduced a feature that detects attempts to send SMS messages to special rate numbers, also known as short codes, and prompts users for confirmation. Unfortunately, due to the Android market fragmentation, only 4 percent of Android devices are currently running Android 4.2.x.

This estimation is based on data collected from Google Play over a 14-day period ending on May 1, 2013, the Juniper researchers said. Based on the same data, the most common versions of Android found on devices are Android 2.3.3 to 2.3.7, also known as "Gingerbread," with a 36.4 percent coverage and Android 4.0.3 and 4.0.4, also known as "Ice Cream Sandwich," with 25.5 percent.

The lack of regular updates for Android devices contributes to the growth of Android malware, because the latest protections added by Google to the operating systems reach users too late or never, the researchers said.

The second most common type of Android threats are spyware applications that capture and transfer sensitive user data to attackers. These account for 19 percent of all malicious samples collected by Juniper's MTC.

Some information-stealing Android Trojan apps discovered during the past year and distributed through drive-by downloads or phishing emails could also pose a threat to enterprise environments, the Juniper researchers said. Data collected from enterprise mobile devices running Juniper's Junos Pulse endpoint collaboration and security software showed at least one infection on 3.1 percent of such devices.

While that figure is not large enough to raise a significant alarm, it is proof that the threat of mobile malware to corporate devices is not only theoretical, the Juniper researchers said. "We expect the presence of mobile malware in the enterprise to grow exponentially in the coming years."

Join the PC World newsletter!

Error: Please check your email address.

Tags Android OSsecuritymobile securityscamsmobilespywarejuniper networksmalwaremobile applications

Our Back to Business guide highlights the best products for you to boost your productivity at home, on the road, at the office, or in the classroom.

Keep up with the latest tech news, reviews and previews by subscribing to the Good Gear Guide newsletter.

Lucian Constantin

IDG News Service
Show Comments

Essentials

Lexar® JumpDrive® S57 USB 3.0 flash drive

Learn more >

Microsoft L5V-00027 Sculpt Ergonomic Keyboard Desktop

Learn more >

Mobile

Lexar® JumpDrive® S45 USB 3.0 flash drive 

Learn more >

Exec

Lexar® Professional 1800x microSDHC™/microSDXC™ UHS-II cards 

Learn more >

Audio-Technica ATH-ANC70 Noise Cancelling Headphones

Learn more >

Lexar® JumpDrive® C20c USB Type-C flash drive 

Learn more >

HD Pan/Tilt Wi-Fi Camera with Night Vision NC450

Learn more >

Budget

Back To Business Guide

Click for more ›

Most Popular Reviews

Latest News Articles

Resources

PCW Evaluation Team

Azadeh Williams

HP OfficeJet Pro 8730

A smarter way to print for busy small business owners, combining speedy printing with scanning and copying, making it easier to produce high quality documents and images at a touch of a button.

Andrew Grant

HP OfficeJet Pro 8730

I've had a multifunction printer in the office going on 10 years now. It was a neat bit of kit back in the day -- print, copy, scan, fax -- when printing over WiFi felt a bit like magic. It’s seen better days though and an upgrade’s well overdue. This HP OfficeJet Pro 8730 looks like it ticks all the same boxes: print, copy, scan, and fax. (Really? Does anyone fax anything any more? I guess it's good to know the facility’s there, just in case.) Printing over WiFi is more-or- less standard these days.

Ed Dawson

HP OfficeJet Pro 8730

As a freelance writer who is always on the go, I like my technology to be both efficient and effective so I can do my job well. The HP OfficeJet Pro 8730 Inkjet Printer ticks all the boxes in terms of form factor, performance and user interface.

Michael Hargreaves

Windows 10 for Business / Dell XPS 13

I’d happily recommend this touchscreen laptop and Windows 10 as a great way to get serious work done at a desk or on the road.

Aysha Strobbe

Windows 10 / HP Spectre x360

Ultimately, I think the Windows 10 environment is excellent for me as it caters for so many different uses. The inclusion of the Xbox app is also great for when you need some downtime too!

Mark Escubio

Windows 10 / Lenovo Yoga 910

For me, the Xbox Play Anywhere is a great new feature as it allows you to play your current Xbox games with higher resolutions and better graphics without forking out extra cash for another copy. Although available titles are still scarce, but I’m sure it will grow in time.

Featured Content

Latest Jobs

Don’t have an account? Sign up here

Don't have an account? Sign up now

Forgot password?