{"id":10898,"date":"2017-12-19T11:10:11","date_gmt":"2017-12-19T19:10:11","guid":{"rendered":"http:\/\/www.palada.net\/index.php\/2017\/12\/19\/news-4670\/"},"modified":"2017-12-19T11:10:11","modified_gmt":"2017-12-19T19:10:11","slug":"news-4670","status":"publish","type":"post","link":"http:\/\/www.palada.net\/index.php\/2017\/12\/19\/news-4670\/","title":{"rendered":"Lo lo lo Loapi Trojan could break your Android"},"content":{"rendered":"<p><strong>Credit to Author: Nathan Collier| Date: Tue, 19 Dec 2017 18:43:17 +0000<\/strong><\/p>\n<p>Kaspersky\u00a0has found what they deem as a <a href=\"https:\/\/securelist.com\/jack-of-all-trades\/83470\/\" target=\"_blank\" rel=\"noopener\">jack of all trades<\/a> malicious app they call Trojan.AndroidOS.Loapi. Like the\u00a0<a href=\"https:\/\/blog.malwarebytes.com\/cybercrime\/2017\/11\/new-trojan-malware-discovered-google-play\/\" target=\"_blank\" rel=\"noopener\">Trojan AsiaHitGroup<\/a> we discovered last month on Google Play, this malware can do all the things\u2014it&#8217;s a downloader, dropper, SMS Trojan, and can push ads all from the same malicious app. If left to its own devices, it could overheat the phone by taxing the processor, make the battery bulge, and essentially leave your <a href=\"https:\/\/www.bleepingcomputer.com\/news\/security\/android-malware-will-destroy-your-phone-no-ifs-and-buts-about-it\/\" target=\"_blank\" rel=\"noopener\">Android for dead<\/a>.<\/p>\n<p>It seems creating Swiss army knife malware\u2014lumping several uniquely malicious features into one catch-all malicious app\u2014is becoming a trend. At least this time, the Loapi Trojan didn&#8217;t make it onto Google Play.<\/p>\n<h3>Loapi capabilities<\/h3>\n<p>For the purpose of hiding itself, Loapi poses (mostly) as a fake antivirus or, on the other end of the spectrum, adult content apps. It then asks for device administrator permissions to lock the screen of the mobile device, among other things. Furthermore, it takes the damage to another level by attempting to trick the user into thinking genuine anti-malware scanners are the real threat, and prompts to uninstall them if found. If that weren&#8217;t enough, it comes with a host of other features, including:<\/p>\n<ul>\n<li><a href=\"https:\/\/en.wikipedia.org\/wiki\/Cryptocurrency\" target=\"_blank\" rel=\"noopener\">Cryptocurrency <\/a>mining using the <a href=\"https:\/\/getmonero.org\/\" target=\"_blank\" rel=\"noopener\">Monero<\/a> platform<\/li>\n<li><a href=\"https:\/\/blog.malwarebytes.com\/cybercrime\/2017\/10\/mobile-menace-monday-despicable-adware\/\" target=\"_blank\" rel=\"noopener\">Aggressively displaying advertisements\u00a0<\/a><\/li>\n<li>Sending\/deleting\/replying to SMS messages for the main purpose of Command &amp; Control (C&amp;C) capabilities<\/li>\n<li>Web crawling to subscribe the victim to various pay-for services<\/li>\n<li><a href=\"https:\/\/en.wikipedia.org\/wiki\/Denial-of-service_attack\" target=\"_blank\" rel=\"noopener\">DDoS attacking<\/a> capability via a barrage of HTTP requests from the victim&#8217;s device<\/li>\n<\/ul>\n<p class=\"p1\"><span class=\"s1\">With everything going on in the background, Loapi puts an extreme load on the mobile device. This can lead to the Android literally blowing up from heat produced by the maxed-out processor and battery.<\/span><\/p>\n<p>To state the obvious: This Loapi Trojan is quite nasty.<\/p>\n<h3>Darn it, tell me if you detect it or not already!<\/h3>\n<p>So, do we detect this monster? You bet we do! Our Malwarebytes for Android detection name is Android\/Trojan.Dropper.Agent.BGT. You&#8217;ll be delighted to know that we&#8217;ve been on top of this bad boy since October.<\/p>\n<p>In <a href=\"https:\/\/play.google.com\/store\/apps\/details?id=org.malwarebytes.antimalware\" target=\"_blank\" rel=\"noopener\">Malwarebytes for Android<\/a>, detection of this infection is primarily done by our advanced deep scanner, which uses <a href=\"https:\/\/en.wikipedia.org\/wiki\/Heuristic_(computer_science)\" target=\"_blank\" rel=\"noopener\">heuristic<\/a> methodology to find malware, such as this Trojan, deeply embedded in the device. Deep scan is a feature in our Premium version. Therefore, if you want to stay protected in real time against Loapi, we recommend you upgrade to Premium after your free 30-day trial of Malwarebytes for Android. Stay safe out there!<\/p>\n<p>The post <a rel=\"nofollow\" href=\"https:\/\/blog.malwarebytes.com\/cybercrime\/2017\/12\/lo-lo-lo-lo-loapi-we-have-you-protected\/\">Lo lo lo Loapi Trojan could break your Android<\/a> appeared first on <a rel=\"nofollow\" href=\"https:\/\/blog.malwarebytes.com\">Malwarebytes Labs<\/a>.<\/p>\n<p><a href=\"https:\/\/blog.malwarebytes.com\/cybercrime\/2017\/12\/lo-lo-lo-lo-loapi-we-have-you-protected\/\" target=\"bwo\" >https:\/\/blog.malwarebytes.com\/feed\/<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p><strong>Credit to Author: Nathan Collier| Date: Tue, 19 Dec 2017 18:43:17 +0000<\/strong><\/p>\n<table cellpadding='10'>\n<tr>\n<td valign='top' align='center'><a href='https:\/\/blog.malwarebytes.com\/cybercrime\/2017\/12\/lo-lo-lo-lo-loapi-we-have-you-protected\/' title='Lo lo lo Loapi Trojan could break your Android'><img src='https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2017\/12\/shutterstock_385239634.jpg' border='0'  width='300px'  \/><\/a><\/td>\n<\/tr>\n<tr>\n<td valign='top' align='left'>Loapi Trojan discovered on Android devices\u2014a downloader, dropper, adware app, and SMS Trojan all in one\u2014could literally blow up your phone. Read on to learn how to protect against it.<\/p>\n<p>Categories: <\/p>\n<ul class=\"post-categories\">\n<li><a href=\"https:\/\/blog.malwarebytes.com\/category\/cybercrime\/\" rel=\"category tag\">Cybercrime<\/a><\/li>\n<li><a href=\"https:\/\/blog.malwarebytes.com\/category\/cybercrime\/mobile\/\" rel=\"category tag\">Mobile<\/a><\/li>\n<\/ul>\n<p>Tags: <a href=\"https:\/\/blog.malwarebytes.com\/tag\/android\/\" rel=\"tag\">Android<\/a><a href=\"https:\/\/blog.malwarebytes.com\/tag\/loapi\/\" rel=\"tag\">loapi<\/a><a href=\"https:\/\/blog.malwarebytes.com\/tag\/mobile\/\" rel=\"tag\">Mobile<\/a><a href=\"https:\/\/blog.malwarebytes.com\/tag\/trojan\/\" rel=\"tag\">trojan<\/a><\/p>\n<table width='100%'>\n<tr>\n<td align=right>\n<p><b>(<a href='https:\/\/blog.malwarebytes.com\/cybercrime\/2017\/12\/lo-lo-lo-lo-loapi-we-have-you-protected\/' title='Lo lo lo Loapi Trojan could break your Android'>Read more&#8230;<\/a>)<\/b><\/p>\n<\/td>\n<\/tr>\n<\/table>\n<\/td>\n<\/tr>\n<\/table>\n<p>The post <a rel=\"nofollow\" href=\"https:\/\/blog.malwarebytes.com\/cybercrime\/2017\/12\/lo-lo-lo-lo-loapi-we-have-you-protected\/\">Lo lo lo Loapi Trojan could break your Android<\/a> appeared first on <a rel=\"nofollow\" href=\"https:\/\/blog.malwarebytes.com\">Malwarebytes Labs<\/a>.<\/p>\n","protected":false},"author":4,"featured_media":0,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"colormag_page_container_layout":"default_layout","colormag_page_sidebar_layout":"default_layout","footnotes":""},"categories":[10488,10378],"tags":[10462,4503,16992,10554,10833],"class_list":["post-10898","post","type-post","status-publish","format-standard","hentry","category-malwarebytes","category-security","tag-android","tag-cybercrime","tag-loapi","tag-mobile","tag-trojan"],"_links":{"self":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts\/10898","targetHints":{"allow":["GET"]}}],"collection":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/users\/4"}],"replies":[{"embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/comments?post=10898"}],"version-history":[{"count":0,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts\/10898\/revisions"}],"wp:attachment":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/media?parent=10898"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/categories?post=10898"},{"taxonomy":"post_tag","embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/tags?post=10898"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}