TimpDoor Android Proxy Malware
This content has been archived
This article no longer conforms to NHS Digital's standards for cyber alerts, and may contain outdated or inaccurate information. Use of this information contained in this page is at your own risk
Summary
Affected platforms
The following platforms are known to be affected:
Threat details
Unlike most Android malware, TimpDoor is not installed through the Google Play Store, but is instead delivered as a malicious link in SMS and IM messages. When opened, these links direct to a webpage disguised as a legitimate website, where the user will be asked to install an application.
Once installed, TimpDoor will initiate a secure shell connection to a command and control (C2) server before hiding itself. It will then create a SOCKS proxy and begin forwarding user, device and network information to the C2 server. Traffic can also be sent to the proxy, allowing an attacker to bypass network-based security measures.
Remediation advice
Users are advised to only install trusted applications on their devices. Organisations should consider restricting user accounts on corporate devices or using application whitelisting.Remediation steps
| Type | Step |
|---|---|
|
Last edited: 17 February 2020 12:55 pm