{"id":6205,"date":"2012-02-29T17:36:30","date_gmt":"2012-03-01T00:36:30","guid":{"rendered":"http:\/\/blog.webroot.com\/?p=6205"},"modified":"2018-01-30T10:40:26","modified_gmt":"2018-01-30T17:40:26","slug":"an-evolution-of-android-malware-when-stealing-data-isnt-enough-meet-gomanag-part-2","status":"publish","type":"post","link":"https://www.webroot.com/blog/2012\/02\/29\/an-evolution-of-android-malware-when-stealing-data-isnt-enough-meet-gomanag-part-2\/","title":{"rendered":"An Evolution of Android Malware \u201cWhen stealing data isn\u2019t enough meet&#8230;GoManag &#8230;\u201c (Part 2)"},"content":{"rendered":"<p>In our continued series of how Android malware authors continue adding functionality to their work we take a look at GoManag. First seen last year, targeting Chinese speakers, GoManag is a Trojan that installs as a service so it can run in the background, collects device information and downloads payloads.\u00a0 Its odd name comes from part of a URL it attempts to contact to.<\/p>\n<p>Malicious GoManag app running in the background as the name \u201cGoogle Search (Enhanced)\u201d<\/p>\n<p><a href=\"http:\/\/webrootblog.files.wordpress.com\/2012\/02\/gomanag_1.jpg\"><img decoding=\"async\" loading=\"lazy\" class=\"aligncenter size-medium wp-image-6207\" title=\"gomanag_1\" alt=\"\" src=\"http:\/\/webrootblog.files.wordpress.com\/2012\/02\/gomanag_1.jpg?w=201\" width=\"201\" height=\"300\" \/><\/a><\/p>\n<p><!--more-->The first variant contained the following permissions:<\/p>\n<p>ACCESS_NETWORK_STATE<\/p>\n<p>INTERNET<\/p>\n<p>WAKE_LOCK<\/p>\n<p>READ_SMS<\/p>\n<p>WRITE_EXTERNAL_STORAGE<\/p>\n<p>READ_PHONE_STATE<\/p>\n<p>It has functionality to do the following things in the background:<\/p>\n<p>-read text messages<\/p>\n<p style=\"text-align: center;\"><a href=\"http:\/\/webrootblog.files.wordpress.com\/2012\/02\/gomang02.jpg\"><img decoding=\"async\" loading=\"lazy\" class=\"aligncenter size-medium wp-image-6216\" title=\"gomang02\" alt=\"\" src=\"http:\/\/webrootblog.files.wordpress.com\/2012\/02\/gomang02.jpg?w=300\" width=\"300\" height=\"220\" \/><\/a><\/p>\n<p>&#8211; Uninstall security app 360Safe<\/p>\n<p style=\"text-align: center;\"><a href=\"http:\/\/webrootblog.files.wordpress.com\/2012\/02\/gomanag_3.jpg\"><img decoding=\"async\" loading=\"lazy\" class=\"aligncenter  wp-image-6209\" title=\"gomanag_3\" alt=\"\" src=\"http:\/\/webrootblog.files.wordpress.com\/2012\/02\/gomanag_3.jpg\" width=\"528\" height=\"275\" \/><\/a><\/p>\n<p>-Get phone information<\/p>\n<p style=\"text-align: center;\"><a href=\"http:\/\/webrootblog.files.wordpress.com\/2012\/02\/gomanag_4.jpg\"><img decoding=\"async\" loading=\"lazy\" class=\"aligncenter size-medium wp-image-6210\" title=\"gomanag_4\" alt=\"\" src=\"http:\/\/webrootblog.files.wordpress.com\/2012\/02\/gomanag_4.jpg?w=300\" width=\"300\" height=\"170\" \/><\/a><\/p>\n<p>&#8211; Download and install APKs<\/p>\n<p style=\"text-align: center;\"><a href=\"http:\/\/webrootblog.files.wordpress.com\/2012\/02\/gomanag_5.jpg\"><img decoding=\"async\" loading=\"lazy\" class=\"size-medium wp-image-6211 aligncenter\" title=\"gomanag_5\" alt=\"\" src=\"http:\/\/webrootblog.files.wordpress.com\/2012\/02\/gomanag_5.jpg?w=300\" width=\"300\" height=\"206\" \/><\/a><\/p>\n<p>The newer variant contains the same permissions as the first, but with these added permissions:<\/p>\n<p>ACCESS_WIFI_STATE<\/p>\n<p>CHANGE_WIFI_STATE<\/p>\n<p>RECEIVE_SMS<\/p>\n<p>SEND_SMS<\/p>\n<p>WRITE_APN_SETTINGS<\/p>\n<p>WRITE_SMS<\/p>\n<p>The new variant does adds to the existing functionality of the previous version:<\/p>\n<p>&#8211; Send SMS<\/p>\n<p><a href=\"http:\/\/webrootblog.files.wordpress.com\/2012\/02\/gomanag_6.jpg\"><img decoding=\"async\" loading=\"lazy\" class=\"aligncenter size-medium wp-image-6212\" title=\"gomanag_6\" alt=\"\" src=\"http:\/\/webrootblog.files.wordpress.com\/2012\/02\/gomanag_6.jpg?w=300\" width=\"300\" height=\"171\" \/><\/a><\/p>\n<p>&#8211; Collects sent SMS Addresses<\/p>\n<p><a href=\"http:\/\/webrootblog.files.wordpress.com\/2012\/02\/gomanag_7.jpg\"><img decoding=\"async\" loading=\"lazy\" class=\"aligncenter size-medium wp-image-6230\" title=\"gomanag_7\" alt=\"\" src=\"http:\/\/webrootblog.files.wordpress.com\/2012\/02\/gomanag_7.jpg?w=300\" width=\"300\" height=\"115\" \/><\/a><\/p>\n<p>&#8211; Blacklist Numbers<\/p>\n<p><a href=\"http:\/\/webrootblog.files.wordpress.com\/2012\/02\/gomanag_8.jpg\"><img decoding=\"async\" loading=\"lazy\" class=\"aligncenter size-medium wp-image-6231\" title=\"gomanag_8\" alt=\"\" src=\"http:\/\/webrootblog.files.wordpress.com\/2012\/02\/gomanag_8.jpg?w=300\" width=\"300\" height=\"147\" \/><\/a><\/p>\n<p>&#8211; Delete Addresses<\/p>\n<p><a href=\"http:\/\/webrootblog.files.wordpress.com\/2012\/02\/gomanag_9.jpg\"><img decoding=\"async\" loading=\"lazy\" class=\"aligncenter size-medium wp-image-6232\" title=\"gomanag_9\" alt=\"\" src=\"http:\/\/webrootblog.files.wordpress.com\/2012\/02\/gomanag_9.jpg?w=300\" width=\"300\" height=\"134\" \/><\/a><\/p>\n<p>&#8211; Uninstall APKs<\/p>\n<p><a href=\"http:\/\/webrootblog.files.wordpress.com\/2012\/02\/gomanag_10.jpg\"><img decoding=\"async\" loading=\"lazy\" class=\"aligncenter size-medium wp-image-6229\" title=\"gomanag_10\" alt=\"\" src=\"http:\/\/webrootblog.files.wordpress.com\/2012\/02\/gomanag_10.jpg?w=300\" width=\"300\" height=\"212\" \/><\/a><\/p>\n<p>In just a couple of months the capabilities of this spyware has grown quite a bit.\u00a0 Something like this is hard to spot running on your Android device.\u00a0 Would you think something called \u201cGoogle Search (Enhanced)\u201d would be malicious?\u00a0 This is where it&#8217;s important to have Webroot SecureAnywhere installed on your Android device to be able detect this well hidden spyware and other malicious apps like it.<\/p>\n<p>If you&#8217;re attending the RSA conference this week in San Francisco and want to know more about the process behind Andorid malware stop by room 104 at\u00a010:40 a.m. on day 4 of the conference (Thursday, March 1st) to see\u00a0Senior Threat Research Analyst Armando Orozco and Webroot&#8217;s Manager of Threat Research, Grayson Milbourne present\u00a0&#8220;Cracking Open the Phone: An Android Malware Automated Analysis Primer&#8221;. Hope to see you there!<\/p>\n","protected":false},"excerpt":{"rendered":"<p>In our continued series of how Android malware authors continue adding functionality to their work we take a look at GoManag. First seen last year, targeting Chinese speakers, GoManag is a Trojan that installs as a service so it can run in the background, collects device information and downloads payloads.\u00a0 Its odd name comes from [&hellip;]<\/p>\n","protected":false},"author":65,"featured_media":17051,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":[],"categories":[3005],"tags":[],"yst_prominent_words":[4037,8631,8629,9119,10249,10251,3615,10247,10245,4359,10241,3557,4065,3477,5247,10001,10243,4061,3471,5439],"acf":[],"_links":{"self":[{"href":"https://www.webroot.com/blog/wp-json\/wp\/v2\/posts\/6205"}],"collection":[{"href":"https://www.webroot.com/blog/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https://www.webroot.com/blog/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https://www.webroot.com/blog/wp-json\/wp\/v2\/users\/65"}],"replies":[{"embeddable":true,"href":"https://www.webroot.com/blog/wp-json\/wp\/v2\/comments?post=6205"}],"version-history":[{"count":3,"href":"https://www.webroot.com/blog/wp-json\/wp\/v2\/posts\/6205\/revisions"}],"predecessor-version":[{"id":13657,"href":"https://www.webroot.com/blog/wp-json\/wp\/v2\/posts\/6205\/revisions\/13657"}],"wp:featuredmedia":[{"embeddable":true,"href":"https://www.webroot.com/blog/wp-json\/wp\/v2\/media\/17051"}],"wp:attachment":[{"href":"https://www.webroot.com/blog/wp-json\/wp\/v2\/media?parent=6205"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https://www.webroot.com/blog/wp-json\/wp\/v2\/categories?post=6205"},{"taxonomy":"post_tag","embeddable":true,"href":"https://www.webroot.com/blog/wp-json\/wp\/v2\/tags?post=6205"},{"taxonomy":"yst_prominent_words","embeddable":true,"href":"https://www.webroot.com/blog/wp-json\/wp\/v2\/yst_prominent_words?post=6205"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}