Another Week, Another Dangerous Mobile Firmware Vulnerability
ID: 2cf10b51-a162-573e-bb61-313f3e30d25b
STIX ID: report--2cf10b51-a162-573e-bb61-313f3e30d25b
Feed Name: Security Ledger
Anubis Networks found a hidden Ragentek component embedded in low-cost Android phone firmware that uses an unencrypted over-the-air update channel and hard-coded domains to receive commands and updates. The mechanism can execute arbitrary code with root privileges and includes behavior resembling a rootkit; researchers observed devices (≈2.8 million across 55 models) attempting to contact the embedded domains. Because some domains were unregistered, attackers could register them or perform MITM attacks to take control of large numbers of devices; Anubis has since taken control of the unused domains to reduce risk.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
