Doctor Web Reviews Mobile Threats in December 2013
OREANDA-NEWS. Russian anti-virus company Doctor Web would like to draw your attention to its review of mobile threats for the last month of the year just ended. The review is based on statistics collected with the aid of users who have installed and run the new, ninth version of Dr.Web for Android on their mobile devices. A total of 4,637,717 malicious or unauthorized applications were discovered on handhelds in the period from December 4-25, 2013, i.e., from the moment the new version of Dr.Web for Android was released.
Adware.Revmob.origin.1 (525,500 times), Adware.Airpush.origin.7 (476,304 times) and Adware.Airpush.origin.21 (387,881 times) were the programs most frequently detected. Android.SmsSend.origin.749 became the most “popular” malicious program (249,405 incidents). The top 20 undesirable and malicious applications found in December on mobile devices are listed in the table below.
№ |
Name |
Quantity |
1 |
Adware.Revmob.origin.1 |
525 500 |
2 |
Adware.Airpush.origin.7 |
476 304 |
3 |
Adware.Airpush.origin.21 |
387 881 |
4 |
Android.SmsSend.origin.749 |
249 405 |
5 |
Adware.Leadbolt.origin.7 |
240 274 |
6 |
Android.SmsSend.origin.872 |
234 596 |
7 |
Android.SmsSend.origin.990 |
126 982 |
8 |
Adware.Revmob.origin.3 |
125 555 |
9 |
Android.SmsSend.origin.315 |
101 150 |
10 |
Adware.Startapp.origin.8 |
95 639 |
11 |
Adware.Revmob.origin.2 |
91 756 |
12 |
Android.Subser.origin.1 |
78 124 |
13 |
Adware.Startapp.origin.5 |
67 906 |
14 |
Android.SmsSend.origin.987 |
66 512 |
15 |
Adware.Leadbolt.origin.5 |
64 833 |
16 |
Adware.Airpush.origin.3 |
62 143 |
17 |
Adware.Callflakes.origin.1 |
55 225 |
18 |
Android.SmsSend.origin.309 |
53 138 |
19 |
Android.SmsSend.origin.758 |
52 815 |
20 |
Android.SmsSend.origin.908 |
52 372 |
The statistics lead to the conclusion that various Android.SmsSend Trojan modifications remain the most common threats to Android. Also, Dr.Web anti-virus software for Android effectively neutralises various applications that display annoying ads on the screens of smart phones and tablets.
Whenever a malicious or unwanted program was detected, users most often removed it-this happened in 65.5% of incidents. In 27% of cases, the application was not yet installed but stored on the memory card or in the internal memory as an apk file that was removed by the anti-virus. A minor portion of users (4%) moved detected threats to the quarantine. Only 1.8% of users ignored danger warnings from the anti-virus and continued using the infected device, and another 1.4% immediately cancelled the installation of malicious applications on their mobile phones and tablets upon receiving an alert from the anti-virus program.
Samsung Galaxy S III became the most popular device among users of Dr.Web for Android in December-it accounted for 10.72% of the devices on which Dr.Web anti-virus software was installed. Samsung Galaxy S II ranks second with 5.19% of installations, Samsung Galaxy S IV ranks third with 4.70%, and Samsung Galaxy Note II ranks fourth-4.53% of Dr.Web for Android installations occurred on this device. Our users' preferences regarding Android-device manufacturer are shown in the chart below.
In addition to the threats that pose a danger to Android, Dr.Web for Android often detected and neutralised some malicious programs for Windows-those that penetrated devices while they were connected to a desktop or a laptop and used them as portable storage devices to spread further. Thus, 12,755 copies of the worm Win32.HLLW.Olala were identified and removed from mobile devices in December 2013. The mobile Dr.Web virus database contains multiple entries for malware that can replicate itself to removable media. In addition, Dr.Web promptly detected and removed numerous cross-platform Trojans of the Java.SMSSend family which can work on any mobile device that supports Java.
Doctor Web's analysts will continue to monitor the statistics and inform users about the latest threats and the overall security situation.
Комментарии