DoNot Firestarter Malware Using Google Firebase Cloud Messaging: Report

Popular

RBI asks HDFC Bank to stop digital launches and credit card...

The Reserve Bank of India (RBI) has asked the country's largest private sector lender, HDFC bank to stop all launches of its digital business...

Assam’s Dibrugarh University Teacher Arrested For Sharing Porn Video: Police

During interrogation, the accused confessed to the crime. (Representational)Dibrugarh: An assistant professor in Assam's Dibrugarh University was arrested today for allegedly uploading pornographic content...

Process to avail full refund on Lockdown Air Tickets

The Supreme Court approved the Directorate General of Civil Aviation's (DGCA) proposal on air tickets refund and credit shell on flights booked prior and...

Why was CDS Gen. Bipin Rawat’s attending China-owned MG Motor event;...

US Ambassador Kenneth Juster greets CDS Gen Bipin Rawat with elbow bump | Watch ...

Explained: How new H-1B visa regime will impact Indians, Indian firms

In yet another policy stance change on H-1B visa within six months, the US administration on October 6 said it was announcing an “interim...

DoNot Firestarter is a newly detected malware on Android that is reportedly using Google’s own infrastructure to deliver malware. According to Cisco’s Talos cybersecurity researchers, Firestarter uses Google’s Firebase Cloud Messaging infrastructure to control the malware. Using Google’s infrastructure allows the malware to hide amidst legitimate Internet traffic, and also allows the malware to be targeted in a personalised manner, making it even harder for security researchers to detect.

Analysis of DoNot’s activities by cyber threat researchers at Cisco Talos says that the group tries to specifically target government officials in Pakistan, and NGOs working in Kashmir.

The loader is usually disguised as an application that a user is lured into installing. The app then contains additional code that is used to download the payload, based on the information gained from the device. This could be used — for example — to create an app that is innocuous in the rest of the world but acts as malware in a specific geography.

The malware then transmits personal and geographical information about the device to DoNot’s C2, or its command centre, which helps the group identify the user and decide whether or not to infect the device. The researchers said that by using Google FCM, the malware can receive a malicious package from the DoNot C2 in the form of a link, which would give the group access to the device. And even if a particular C2 was to be taken down, access through the Google FCM would allow the group to infect the device using a different C2, making this loader particularly dangerous and difficult to weed out.
The only way to neutralise the threat, researchers say, would be for Google to take down the infected FCM account, along with the C2. The analysis also says that being specific in targeting users, the DoNot Firestarter malware is hard to be detected and categorised by security researchers.


Is Android One holding back Nokia smartphones in India? We discussed this on Orbital, our weekly technology podcast, which you can subscribe to via Apple Podcasts, Google Podcasts, or RSS, download the episode, or just hit the play button below.

For the latest tech news and reviews, follow Gadgets 360 on Twitter, Facebook, and Google News. For the latest videos on gadgets and tech, subscribe to our YouTube channel.

Veer Arjun Singh

Oppo K7x Geekbench Listing, Official Teaser Reveal Key Specifications Ahead of November 4 Launch

Source link

Latest News

Assets under NPS rose to 38% YoY till March 2021: PFRDA

The Pension Fund Regulatory and...

Charges collected on digital transactions in zero-balance accounts have been refunded: SBI clarifies

CBDT had advised Banks to refund the charges collected, if any, on transactions carried out using the digital mode.State Bank of India (SBI) has...

Wipro Q4 Results: Net Profit Rises 28% To Rs 2,972 Crore, Revenue Up 3.9%

<!-- -->Wipro Q4 Results: The company's revenue stood at Rs 16,334 croreIT services company Wipro on Thursday reported its consolidated profit at Rs 2,972 crore...

Amazon announces $250 million fund for SMEs

The company will help build brand new businesses. E-commerce giant Amazon on Thursday announced a $250 million (around ₹1,873 crore) fund that will focus on...

Wipro Gains Ahead Of Fourth Quarter Earnings Announcement

<!-- -->Wipro Share Price Today: Shares were last trading at Rs 2.70 per cent higher at Rs 429.95 on BSEShare price of software services...