Email stealing Android threat imminent?

Email stealing Android threat imminent?

A rogue app that will steal people's emails is coming to an Android app store soon, one security expert has predicted.

Up until now, mobile malware has received plenty of hype, even in lieu of a threat to justify the hysteria.

Yet this is set to change, possibly even before this year is through, according to one security pro.

Before 2011 closes, head of BitDefender Online Threats Lab Catalin Cosoi thinks we will see the first rogue Android app able to intercept and redirect email.

“It is very easy to create a malicious app to take emails and send them somewhere else,” Cosoi explained. “All you need to do is ask for permission. If people want an app, very few will look at permissions.”

So when might we see such an app? “I guess by the end of the year,” Cosoi added.

If such a rogue app does appear, it will be a big threat to business, particularly given the amount of sensitive company data is sent via email, he said.

To dupe users into accepting these permissions, cyber criminals may decide to have their apps pose as productivity software.

Some legitimate productivity applications already ask for permission to access users’ emails. The hugely popular Quickoffice Pro, for instance, asks to be able to read Gmail messages.

A malicious app would do the same, but then send emails to cyber criminals for potential financial gain.

Cosoi said the Google Android security model was flawed, as the company was pandering too much to developers.

Instead of focusing time on ensuring each and every app was perfectly safe for users to download, Google is placing too much emphasis on making it easy for devs to get their software on the Android Market, Cosoi claimed.

“They don’t test security very well,” he added. “[Once you’ve created an app], you only need about two minutes before it is on the market.”

Google said it didn't have a comment on Cosoi's claims, instead pointing to this Android developer policy page.

Time to market?

There is little information on how long it takes to get an app up on the Android Market after creating it, and on whether Cosoi was right in his assertions.

However, Google's online documents hint that much of the power lies in the hands of the developer.

“To publish your application on Android Market, you first need to register with the service using a Google account and agree to the terms of service. Once you are registered, you can upload your application to the service whenever you want, update it as many times as you want, and then publish it when you are ready. Once published, users can see your application, download it and rate it,” the Android Developer site reads.

Nevertheless, Google is fairly convinced its security model protects users.

"A central design point of the Android security architecture is that no application, by default, has permission to perform any operations that would adversely impact other applications, the operating system, or the user," the developer site read.

Android has gained plenty of hacker attention in the past year. McAfee data from last month showed the amount of Android focused malware spiked 76 per cent in Q2 of 2011, when compared to Q1.

Of all new mobile malware created in the second quarter, approximately two thirds was aimed at Android.

According to G Data, mobile malware spiked 273 per cent in the first half of 2011 over the same period in 2010.

This article originally appeared at itpro.co.uk

Source: Copyright © ITPro, Dennis Publishing

See more about:  email  |  stealing  |  android  |  threat  |  imminent  |  phones  |  securitysoftware
 
 

Readers of this article also read...

Telstra supports International Day Against Homophobia, Biphobia and Transphobia 

Telstra supports International Day Against Homophobia, Biphobia and Transphobia

 
Toshiba's new 2013 laptops unveiled 

Toshiba's new 2013 laptops unveiled

 
New list of soon-to-be NBN-enabled suburbs released 

New list of soon-to-be NBN-enabled suburbs released

 
Exclusive First Look: Gigabyte's Z87X-UD3H 

Exclusive First Look: Gigabyte's Z87X-UD3H

 
Samsung Galaxy S4 hits Australia this Saturday 

Samsung Galaxy S4 hits Australia this Saturday

 
Comments: 4
dbareis
29 September 2011
I'd like to authorise each and every required permission seperately (should have suitable defaults) and they should be allow/disallow and ask every time (with ltare option of allows allow) just like a firewall. I may be happy that access to contacts are disallowed, the app should be able to handle that and when I need to do something I know needs contact access I'll allow.


Comment made about the PC & Tech Authority article:
Email stealing Android threat imminent??
A rogue app that will steal people's emails is coming to an Android app store soon, one security expert has predicted.

What do you think? Join the discussion.
amcmo
29 September 2011
Despite all the attempts by Google to fob off discussion, this is a very real issue and one that is already causing grief (despite the article attempting to brush this off as not significant) Simple anti-virus does not appear to be the answer.
ory_zm
29 September 2011
Although most obvious in Android, this is a real issue in almost any application and platform. Do we (users) really know what any piece of software we install does? - No.
The only software that might be considered somewhat safe is open source, and that is only if a trustworthy someone has gone through the effort to check that there is no malicious code in there.
If someone tomorrow releases an app that does something for free that most people pay for (and there are a few examples for something like that, as an office app mentioned in the article) then it is certain that many people will d/l and use it regardless of the permissions it asks for.
Talking about it in tech magazines also does not help as 99% of the population is oblivious to what's going on in places like this.
amcmo
29 September 2011
Thus far, in app stores, the safest is Apples as they do screen the apps very closely.

Open source is no safer than Android'(sort of open source), as anyone has the ability to have a crack at the code.

That's one of the problems with some of the Android app stores out there, crims downloading a genuine app, tweeking the source to add their little mischief, then uploading to one of the secondary app sites.
Comments have been disabled for this article.

Latest Comments

Latest Poll

Which side are you choosing in the new console wars?



or View results
The Xbox One
  25%
 
The PlayStation 4
  30%
 
A console? Good Lord no - PC for me thanks!
  46%
TOTAL VOTES: 134

Vote now
Ads by Google

From our Partners

PC & Tech Authority Downloads