FireEye Labs recently identified malware for Android devices that
masquerades as a Mandiant product. The malware can lock Android
devices and displays a lock screen that uses the Mandiant brand.
To a victim in the United States, this lock screen may appear
as:
style="border: 2.0px solid black;" alt="Figure 1"
src="https://www.fireeye.com/content/dam/legacy/ammo/Figure-16.png"
width="536" height="819" />
To try to make the lock message
more convincing, the criminals can use a different header image
depending on the victim's country:
![]()
class="size-full wp-image-5708 " style="border: 2.0px solid black;"
title="Banner displayed to victims in the US"
alt="Banner displayed to victims in the US"
src="https://www.fireeye.com/content/dam/legacy/ammo/Banner-displayed-to-victims-in-the-US.jpg"
width="1000" height="175" />Banner displayed to victims in the
US
![]()
style="border: 2.0px solid black;"
alt="Banner displayed to victims in Australia"
src="https://www.fireeye.com/content/dam/legacy/ammo/Banner-displayed-to-victims-in-Australia.jpg"
width="1000" height="175" />Banner displayed to victims in
Australia
![]()
style="border: 2.0px solid black;"
alt="Banner displayed to victims in Ireland"
src="https://www.fireeye.com/content/dam/legacy/ammo/Banner-displayed-to-victims-in-Ireland.jpg"
width="1000" height="175" />Banner displayed to victims in
Ireland
![]()
style="border: 2.0px solid black;"
alt="Banner displayed to victims in Poland"
src="https://www.fireeye.com/content/dam/legacy/ammo/Banner-displayed-to-victims-in-Poland.jpg"
width="1000" height="175" />Banner displayed to victims in
Poland
![]()
style="border: 2.0px solid black;"
alt="Banner displayed to victims in France"
src="https://www.fireeye.com/content/dam/legacy/ammo/Banner-displayed-to-victims-in-France.jpg"
width="1000" height="175" />Banner displayed to victims in
France
The Android malware is typically delivered by tricking the
victim into installing it after visiting a malicious website. Once
installed, it will run every time the device boots and displays the
lock screen. The malware can communicate with several command and
control servers using the following domains:
-
police-strong-mobile[.]com
- mobile-policeblock[.]com
-
police-secure-mobile[.]com
- police-scan-mobile[.]com
-
police-mobile-stop[.]com
- police-guard-mobile[.]com
Our
research indicates police-strong-mobile[.]com is actively in use,
and has been online since March 29, 2014.
The apps themselves
are well obfuscated-the method names inside the app are written in
non-meaningful strings. The methods the app calls are constructed
using a 5-byte XOR key dynamically. We have also noticed different
XOR keys used for every different decoding instance. The app also
blocks access to images, and it forces the user to pay a fee to
access the contents.
This isn't the first time that we've
seen cybercriminals trading on Mandiant's brand. Last year, Mandiant
identified PC malware that was locking users' computers and
displaying content saying the system was locked due to criminal
activity. As href="https://www.mandiant.com/blog/malware-mandiants/"
target="_blank">we indicated last year, this is part of a scam
designed to extort money from victims.
We recommend victims
of this malware report the incident to the href="https://www.ic3.gov/default.aspx" target="_blank">Internet
Crime Center.