Google, Lookout Detail 'Chrysaor' Android Malware, Related to Pegasus iOS Malware

Advertisement
By Shekhar Thakran | Updated: 5 April 2017 14:10 IST
Highlights
  • Infected apps were never made available through Google Plays
  • Chrysaor doesn't make use of zero-day vulnerabilities
  • New malware believed to be related to Pegasus

Researchers at Google and mobile security firm Lookout have now discovered that infamous iOS spyware Pegasus, which was described as sophisticated and discovered last year, has now turned up on Android in the form of 'Chrysaor'. Notably, the advanced form of malware can potentially give remote control of the device to the exploiter and even deletes itself, remove all traces.

Before you start getting uneasy, Google has clarified that the infected apps that carried the malware were never made available through Google Play store. Further, Google said that it tried to find the scope of Chrysaor by using Verify Apps, only to find that it had low volumes of installs outside Google Play. As per search giant, Israel-based NSO Group Technologies, which was behind the Pegasus malware is believed to be behind Chrysaor as well.

"Late last year, after receiving a list of suspicious package names from Lookout, we discovered that a few dozen Android devices may have installed an application related to Pegasus, which we named Chrysaor," Google said in a post. "Among the over 1.4 billion devices protected by Verify Apps, we observed fewer than 3 dozen installs of Chrysaor on victim devices," it added.

Advertisement

As per the search giant, the Chrysaor malware has been targeted at devices running Android 4.3 Jelly Bean or earlier versions.

Advertisement

Some of the spying functionalities in the Chrysaor malware include keylogging, screenshot capture, Live audio capture, remote control of the malware via SMS, browser history exfiltration, email exfiltration from Android's native email client, contacts and text message, as per Lookout. It also enables messaging data exfiltration from common applications including WhatsApp, Skype, Facebook, Twitter, Viber, Kakao.

The Chrysaor malware self destructs itself when it finds its position in danger and meets certain conditions, Lookout points out. "It's clear that this malware was built to be stealthy, targeted, and is very sophisticated," Lookout said in its post regarding the malware.

Advertisement

The most notable difference between Chrysaor on Android and Pegasus on iOS is that the former doesn't use zero-day vulnerabilities to root the device. Chrysaor instead uses a well-known rooting technique called Framaroot.

"In the case of Pegasus for iOS, if the zero-day attack execution failed to jailbreak the device, the attack sequence failed overall. In the Android version, however, the attackers built in functionality that would allow Pegasus for Android to still ask for permissions that would then allow it to access and exfiltrate data. The failsafe jumps into action if the initial attempt to root the device fails," Lookout said.

Advertisement

As the Chrysaor malware has not been distributed at large scale, majority of Android devices are out of danger but we would like to warn our readers who are using Android not to install apps from unverified sources in order to keep their devices secure

 

Get your daily dose of tech news, reviews, and insights, in under 80 characters on Gadgets 360 Turbo. Connect with fellow tech lovers on our Forum. Follow us on X, Facebook, WhatsApp, Threads and Google News for instant updates. Catch all the action on our YouTube channel.

Advertisement
Popular Mobile Brands
  1. Motorola Edge 70 Ultra Camera Configuration, Other Key Features Leaked
  2. Nothing Phone 4a Series Price and Key Specs Tipped
  3. Realme Narzo 90 Series Price in India Leaked; Will Come in These Colourways
  4. Dominic and the Ladies' Purse OTT Release Date: When and Where to Watch it Online?
  5. Star's Wobble Around Black Hole Confirms Einstein's Century-Old Prediction
  6. Hogwarts Legacy Is Currently Free on Epic Games Store: How to Redeem
  7. The Rookie Season 7 OTT Release Date: When and Where to Watch it Online?
  8. Galaxy Mergers Can Switch On Supermassive Black Holes, Euclid Finds
  1. Astronomers Observe Star’s Wobbling Orbit, Confirming Einstein’s Frame-Dragging
  2. Galaxy Collisions Found to Activate Supermassive Black Holes, Euclid Data Shows
  3. JWST Detects Oldest Supernova Ever Seen, Linked to GRB 250314A
  4. Chandra’s New X-Ray Mapping Exposes the Invisible Engines Powering Galaxy Clusters
  5. Blue Origin to Fly First Wheelchair User to Space on New Shepard NS-37
  6. Chandra’s New X-Ray Mapping Exposes the Invisible Engines Powering Galaxy Clusters
  7. Sasivadane Now Streaming on Amazon Prime Video: Everything You Need to Know
  8. Kuttram Purindhavan Now Streaming Online: What You Need to Know?
  9. Lyne Lancer 19 Pro With 2.01-Inch Display, SpO2 Monitoring Launched in India
  10. OpenAI and Disney Reach Licensing Agreement to Bring Its Characters to the Sora App
Gadgets 360 is available in
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2025. All rights reserved.