ZNIU is First Android Malware Exploiting Dirty COW Vulnerability

Advertisement
By Ketan Pratap | Updated: 26 September 2017 17:16 IST
Highlights
  • Over 5,000 users have been so far affected by the malware
  • 1,200 malicious Android apps have been discovered
  • Most cases of malware were discovered in China and India

Security researchers have discovered the first instance of Dirty COW vulnerability exploitation spotted in an Android malware. The Dirty COW flaw was dubbed so as it is an acronym for the duplication technique called copy-on-write, and could potentially give root access of a device to the attacker within a matter of seconds. Google late last year claimed to have fixed the issue linked to Linux with its December Android Security update. Now, a malware called ZNIU has been confirmed to be using this exploit to infect devices.

To recall, the ZNIU malware was detected last month in over 40 countries, with the majority of the cases reported in China and India. Researchers claim that the malware was also detected in the US, Japan, Canada, Germany, and Indonesia. The researchers were able to detect over 5,000 affected users, and also claim that more than 1,200 malicious apps carried ZNIU exploit. Researchers claim that the ZNIU malware often appeared as a porn app downloaded from malicious website where users are tricked into clicking on a malicious URL that installs the malware-carrying app on their device.

Advertisement

Security researchers Jason Gu, Veo Zhang, and Seven Shen at Trend Micro captured samples of ZNIU (detected as AndroidOS_ZNIU), which is the first malware family to exploit the Dirty COW vulnerability on the Android platform.

"The vulnerability was discovered in upstream Linux platforms such as Redhat, and Android, which kernel is based on Linux. It was categorised as a serious privilege escalation flaw that allows an attacker to gain root access on the targeted system. Dirty COW attack on Android has been silent since its discovery, perhaps because it took attackers some time to build a stable exploit for major devices," the researchers noted.

Advertisement

The malware used to harvest the carrier information of the user. "It then transacts with the carrier through an SMS-enabled payment service, allowing the malware operator to pose as the device owner. Through the victim's mobile device, the operator behind ZNIU will collect money through the carrier's payment service," explain researchers.

"We have detected more than 5,000 affected users. Our data also shows that more than 1,200 malicious apps that carry ZNIU were found in malicious websites with an existing rootkit that exploits Dirty COW, disguising themselves as pornography and game apps, among others."

Advertisement

Researchers also claim that the Dirty COW vulnerability can exploit all versions of Android OS. However, ZNIU-infected Dirty COW exploit only works on devices running Android OS with ARM/X86 64-bit architecture.

 

Get your daily dose of tech news, reviews, and insights, in under 80 characters on Gadgets 360 Turbo. Connect with fellow tech lovers on our Forum. Follow us on X, Facebook, WhatsApp, Threads and Google News for instant updates. Catch all the action on our YouTube channel.

Further reading: Android, Dirty COW, Linux, Trend Micro
Advertisement

Related Stories

Popular Mobile Brands
  1. Poco X8 5G Appears on Geekbench Website
  2. Apple Leadership Shakeup: Phil Schiller Gives Up App Store, Events Roles
  3. Poco X8 Power Will Be Powered by This Snapdragon Chipset
  4. Vivo X500 Pro Max Camera Sample Revealed; Leak Reveals Huge Island
  5. Philips 5G Smartphone Set to Launch in India on This Date
  6. Redmi Note 17 Pro Max 5G India Launch Teased
  7. Here's Your First Look at Oppo's ColorOS 17 New Design and Animations
  8. Samsung May Bring Scam Detection to Galaxy S27 and Older Flagships
  9. Xiaomi UltraThin Magnetic Power Bank Set to Launch in India on This Date
  10. Xiaomi 18 Fold Appears on Geekbench Website Ahead of Launch
  1. Xiaomi 18 Fold With Xring O3 Chip Allegedly Surfaces on Geekbench Ahead of Launch
  2. Samsung Galaxy S27 Series May Get Scam Detection Alongside Galaxy S25 Series, and Older Flagships
  3. MEXC Introduces Crypto Visa Card With USDT Cashback and Apple Pay Integration
  4. Poco X8, Poco X8 Power Key Specifications and Features Announced Ahead of India Launch
  5. Oppo Find X9s, Xiaomi Pad 8, Redmi Pad 2, Redmi 15A Prices Hiked in India by Up to Rs 5,000
  6. Redmi K100 Tipped to Get 10,000mAh Battery, Ultra-High Refresh Rate Display
  7. Sony Launches Live TV Service on PS5, Bringing Movies, TV Shows, Sports and More to PlayStation Console
  8. Oppo Teases Android 17-Based ColorOS 17 With Fresh Animations and UI Design
  9. Samsung Galaxy S27 Series Could See Major Camera Hardware Changes: Here's What You Need to Know
  10. Xiaomi UltraThin Magnetic Power Bank 5000 15W India Launch Date Revealed; Magnetic Power Bank 10000 45W to Tag Along
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2026. All rights reserved.