By continuing to use the site or forum, you agree to the use of cookies, find out more by reading our GDPR policy

A widely circulating piece of Android malware primarily targeting US-based phones used a clever trick to reinfect one of its targets in a feat that stumped researchers as to precisely how it was pulled off. xHelper came to light last May when a researcher from security firm Malwarebytes published this brief profile. Three months later, Malwarebytes provided a deeper analysis after the company’s Android antivirus app detected xHelper on 33,000 devices mostly located in the US, making the malware one of the top Android threats. The encryption and heavy obfuscation made analysis hard, but Malwarebytes researchers ultimately concluded that the main purpose of the malware was to act as a backdoor that could remotely receive commands and install other apps. On Wednesday, Malwarebytes published a new post that recounted the lengths one Android user took to rid her device of the malicious app. In short, every time she removed two xHelper variants from the device, the malware would reappear on her device within the hour. She reported that even performing a factory reset wasn't enough to make the malware go away. Company researchers initially suspected that pre-installed malware was the culprit. They eventually dropped that theory after the user performed a technique that prevented system apps from running. Malwarebytes analysts later saw the malware indicating that Google Play was the source of the reinfections, but they ruled out this possibility after further investigation. Eventually (and with the help of the Android user), company researchers finally identified the source of the reinfections: several folders on the phone that contained files that, when executed, installed xHelper. All of the folders began with the string com.mufc. To the researchers’ surprise, these folders weren’t removed even though the user performed a factory reset on the device. “This is by far the nastiest infection I have encountered as a mobile malware researcher,” Malwarebytes’ Nathan Collier wrote in Wednesday’s post. “Usually a factory reset, which is the last option, resolves even the worst infection. I cannot recall a time that an infection persisted after a factory reset unless the device came with pre-installed malware.” Hidden inside a directory named com.mufc.umbtts was an Android application package, or APK, that dropped an xHelper variant. The variant, in turn, dropped more malware within seconds. And with that, xHelper once again menaced the user’s device. The user finally rid her device of the malware after using an Android file manager to delete the MUFC folders and all their contents. Because the malware was somehow identifying Google Play as the source of the reinfection, Collier recommends people in a similar position disable the Google Play Store app before removing the folders. There's more posted on OUR FORUM.

It's official. Mobile World Congress, the largest trade show for mobile technology, isn't happening this year. Per a report from Bloomberg, GSMA CEO John Hoffman said that it's now "impossible" for the event to continue due to rising concerns and effects of Coronavirus. Shortly after that initial report came out, the GSMA issued an official press release. It reads: "With due regard to the safe and healthy environment in Barcelona and the host country today, the GSMA has canceled MWC Barcelona 2020 because of the global concern regarding the coronavirus outbreak, travel concern and other circumstances, make it impossible for the GSMA to hold the event. The Host City Parties respect and understand this decision. The GSMA and the Host City Parties will continue to be working in unison and supporting each other for MWC Barcelona 2021 and future editions. Our sympathies at this time are with those affected in China, and all around the world." If you're a little confused by this news, we don't blame you. Just earlier today, the GSMA confirmed that MWC was still taking place despite fears of Coronavirus. However, it was also reported that the organization was actively trying to cancel the trade show, but couldn't as a result of the Spanish government not declaring the virus as a health emergency. Prior to this announcement, we'd seen company after company announces that they were deciding to forgo attending this year's show in an effort to keep the health of its employees safe. This includes the likes of Sony, Nokia, TCL, ZTE, Facebook, Amazon, Apple, and others. Following GSMA's cancellation notice, Microsoft confirmed it will not be present at MWC 2020. "We fully support the GSMA's decision to prioritize the health and welfare of all participants and look forward to sharing Microsoft's latest innovations at a future date," a Microsoft spokesperson said. The decision for GSMA to properly cancel Mobile World Congress isn't all that surprising considering how many attendees were already dropping out and was likely the right call in the grand scheme of things. Even so, it's still a huge blow to the mobile industry. Any planned announcements will now likely come in the form of press releases, so while the information will get out one way or another, there's no getting around the impact of this move. Posted on OUR FORUM.

According to a Wall Street Journal report, the U.S. government officials are claiming Huawei, a phone and telecommunications company with ties to the Chinese government, has the ability to spy on users of mobile phone networks employing Huawei equipment. The claim comes after years of accusations from the U.S. government and repeated denials from Huawei. While Huawei is one of the largest sellers of phones in the world, its original business was building telecommunication networks. However, the U.S. has been wary of allowing Huawei equipment to be incorporated into U.S. telecommunications networks. A 2012 Congressional report effectively banned Huawei from selling the equipment and strongly discouraged U.S. phone companies from selling Huawei phones in their stores. The U.S. wariness comes from concerns regarding Huawei’s ties to the Chinese government—its founder is former Chinese military—and good old-fashioned protectionism. The company has been well positioned provided equipment for the roll-out of affordable and fast 5G networks. “There is no question in my mind that the extra scrutiny Huawei has been under as of late has to do with the political environment between China and the U.S. as well as the high-stakes around AI and 5G,” Lynette Ong, associate professor of Political Science at the University of Toronto, told me via email last year. Ong specializes in Chinese politics and political economy. Last year the U.S. and Huawei traded barbs over the U.S.’s concerns and Huawei’s alleged spying, fraud, and violation of international sanctions against Iran. The furor led to both Australia and New Zealand banning the use of Huawei equipment in telecommunication networks. However some of the largest telecommunication networks in the world, including ones owned by U.K. based Vodafone, and the German Deutsche Telekom AG, currently incorporate Huawei equipment. U.S. officials now claim Huawei has included backdoors into the equipment that effectively allows it to access the same data law enforcement can access. Typically these backdoors, known as “lawful interception interfaces” are used exclusively by law enforcement who must provide warrants to gain access. The equivalent of the old school wiretap, these lawful interception interfaces gives the user of the interface access to any data transmitted over the network, including phone calls and text messages. Looking for more, visit OUR FORUM.