logo

Another Week, Another Dangerous Mobile Firmware Vulnerability

ID: 2cf10b51-a162-573e-bb61-313f3e30d25b

STIX ID: report--2cf10b51-a162-573e-bb61-313f3e30d25b

Feed Name: Security Ledger

Threat Score
75/100

Date Published: 2016-11-21

Date Updated: 2026-04-26

Author: Paul Roberts

...
...

Anubis Networks found a hidden Ragentek component embedded in low-cost Android phone firmware that uses an unencrypted over-the-air update channel and hard-coded domains to receive commands and updates. The mechanism can execute arbitrary code with root privileges and includes behavior resembling a rootkit; researchers observed devices (≈2.8 million across 55 models) attempting to contact the embedded domains. Because some domains were unregistered, attackers could register them or perform MITM attacks to take control of large numbers of devices; Anubis has since taken control of the unused domains to reduce risk.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.