ISC StormCast for Wednesday, October 30th 2019
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)
SANS ISC Handlers
4.9 • 754 Ratings
🗓️ 30 October 2019
⏱️ 6 minutes
🧾️ Download transcript
Summary
Transcript
Click on a timestamp to play from that location
| 0:00.0 | Hello, welcome to the Wednesday, October 30th, 2019 edition of the Sansonet Storms, Stormcast. |
| 0:07.8 | My name is Johannes Ulrich. |
| 0:09.4 | And I'm recording from Jacksonville, Florida. |
| 0:13.9 | Semantic has a brief write-up of X-helper, Android Malaver, that has been on the increase over the last few months according |
| 0:23.6 | to Symantec with about 45,000 devices infected. |
| 0:28.6 | Now what makes this Malver kind of special is that it's very persistent, hard to get rid of, |
| 0:34.6 | and also not that easy to actually notice. It doesn't install itself as a |
| 0:41.3 | regular application but instead just as an application component. What that means for an Android |
| 0:48.7 | user is that you don't see the actual application as part of the regular user interface. |
| 0:56.0 | Instead, it launches itself based on a number of events. |
| 1:01.0 | So, for example, if you connect your phone to power or disconnected from power, if you reboot it, |
| 1:08.0 | and a couple of other actions are linked to this particular application component |
| 1:13.6 | and will start X helper. |
| 1:16.6 | Now once it's up and running it will connect to a command control server, this connection uses |
| 1:22.6 | TLS and also key pinning which means that you can't easily intercept a connection with |
| 1:30.4 | a standard man in the middle proxy. |
| 1:34.0 | Once connected to the command control server, it's then instructed to download and install |
| 1:40.0 | additional components. |
| 1:42.5 | If you manage to exit X Helper, well, it will just start itself again. |
| 1:49.0 | Now the good news if you want to call it that is that this application is not using a particular exploit to install itself. |
| 1:57.0 | It is installed willingly by users as a component of other software they may download. |
| 2:04.6 | So one step of course that you can take to protect yourself is to not download applications |
... |
Please login to see the full transcript.
Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.
Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.
Copyright © Tapesearch 2026.

