A new Android OS virus has been discovered by cybersecurity firm, Kaspersky Lab, and the same is being termed as ‘Switcher Trojan’. The virus infects Android OS powered devices and uses them as tools to infect a user’s Wi-Fi router. It then changes the DNS settings of the router and starts redirecting traffic from the Wi-Fi connected devices to websites controlled and operated by attackers, making users vulnerable to malware, phishing and adware attacks.
What happens is that when an IP address is assigned to a web address, the Switcher Trojan hijacks the process and gives the attackers complete control over the network activity. This works because Wi-Fi routers usually change the DNS settings of all the devices connected to them, and reconfigure them to their own settings.
According to Kaspersky, “The infection is spread by users downloading one of two versions of the Android Trojan from a website created by the attackers. The first version is disguised as an Android client of the Chinese search engine, Baidu, and the other is a well-made fake version of a popular Chinese app for sharing information about Wi-Fi networks.” The company adds that the rogue DNS planted by attackers also has a secondary DNS as a backup, just in case the ongoing rogue DNS goes down. “The Switcher Trojan marks a dangerous new trend in attacks on connected devices and networks. It does not attack users directly. Instead, it turns them into unwilling accomplices: physically moving sources of infection. The Trojan targets the entire network, exposing all its users, whether individuals or businesses, to a wide range of attacks - from phishing to secondary infection. A successful attack can be hard to detect and even harder to shift: the new settings can survive a router reboot, and even if the rogue DNS is disabled, the secondary DNS server is on hand to carry on. Protecting devices is as important as ever, but in a connected world we cannot afford to overlook the vulnerability of routers and Wi-Fi networks,” said Nikita Buchka, mobile security expert, Kaspersky Lab.
The company warns that all users should check their DNS settings and search for the following rogue DNS servers:
If any of these servers are found in DNS settings, then it is recommended that users contact their Internet Service Providers and change login IDs, passwords.
Other Popular Deals
- 10 websites and applications you must know about8 music streaming services worth trying out
- 6 ways to start learning Microsoft AzureHow to improve your Firefox browsing experience
- The 12 most hilarious YouTube channels10 Microsoft Big Data Success Stories
- Next year, these attacks will threaten your cybersecurityWhy you won't need cable or DTH in 2017
- Weird but interesting websites you ought to bookmark right...Daily deals roundup: Discounts on headphones, PC...
- Flipkart New Pinch Days sale: Offers on Google Pixel 2,...10 YouTube sci-tech channels every geek should follow
- 10 reasons to trust Azure with your data15 apps and websites to accomplish everyday tasks
- 15 must have chrome extensionsOn International Internet Day, know your internet