Heimdal Security Blog

New Malware Dubbed AbstractEmu Goes Undetected

A new malware was detected. Named by security researchers AbstractEmu, its attack methods consist of the use of anti-emulation checks and also code abstraction techniques. All these can result in compromised devices rooting with the goal of devices control takeover and system settings tweaking.

The ones who identified the new Android rooting malware under discussion were the Lookout Threat Labs’ security researchers who named it AbstractEmu.

The same experts explained in their report how AbstractEmu posed as functional apps so when a user downloads and opens the app, it will be activated.

AbstractEmu does not have any sophisticated zero-click remote exploit functionality used in advanced APT-style threats, it is activated simply by the user having opened the app. (…) As the malware is disguised as functional apps, most users will likely interact with them shortly after downloading.

Source

Bundled with Apps

According to BleepingComputer, the new malware was bundled with 19 apps that could be found in Google Play or stores that contained third-party apps. We’re talking about Amazon Appstore, Aptoide, Samsung Galaxy Store, or APKPure.

Among the apps that bundled the malware password managers, data savers, and also app launchers could be found. However, these were removed from Google Play following the discovery, but it did not prevent other app stores to distribute them.

Lite Launcher is one of the apps that carried this malware on Android devices with 10,000 downloads registered at the moment of its removal from Google Play.

AbstractEmu: Details on How It Works

AbstractEmu works like this, as per the researchers’ report:

By using the rooting process to gain privileged access to the Android operating system, the threat actor can silently grant themselves dangerous permissions or install additional malware — steps that would normally require user interaction.

Source

What System Info Can It Collect?

Here is a table mentioning what system info AbstractEmu can collect:

Image Source

How to Stay Safe?

Malware makes every headline today: be it a RAT, ransomware, or a virus. We at Heimdal™ keep up with the latest cybersecurity trends and offer you effective solutions. Try our awarded Threat Prevention that will keep you away from threats having stunning accuracy, as it’s designed by means of Machine Learning, AI-based prevention, and cybercrime intelligence.

If you enjoyed this article, because we know that you surely did, don’t forget to follow us on LinkedinTwitterYoutube, or Instagram to never miss a thing we post.