mRAT spyware bypasses mobile enterprise controls
Mobile remote access Trojan (mRAT) infections are increasing and bypassing mobile enterprise security controls, putting businesses at risk of cyber espionage, research has revealed.
mRATs are capable of intercepting third-party applications such as WhatsApp, despite guarantees of encrypted communications, the study of 2 million smartphone users by Lacoon Mobile Security found.
The research also showed that mRATs are similarly able to bypass security controls in mobile device management (MDM) systems, which a growing number of businesses rely-on for mobile security.
mRATs are designed to carry out cyber espionage and typically enable eavesdropping on calls and meetings, extracting information from email and text messages and location tracking of executives.
The spyware requires a backdoor for installation, through the rooting of Google Android or the jailbreaking of Apple iOS devices.
The research found that mRATs can bypass rooting and jailbreaking detection mechanisms installed on handsets, with 52% of infected devices found running iOS and 35% running Android.
The attacks undermine the basic notion of a secure container on which most MDM systems are based, according to Lacoon Mobile Security.
MDM systems create secure containers that separate business and personal data on the mobile, in an attempt to prevent business-critical data from leaking.
However, the research team demonstrated that mRATs do not need to directly attack the encryption mechanism of the secure container, but can grab it at the point where the user pulls up the data to read it.
Mobile best practices and technologies include:
- Remotely analyse the risk involved with each device, including behavioural analysis of the downloaded applications;
- Calculate the risk associated with the device's operating system vulnerabilities and usage;
- Conduct event analysis to uncover new, emerging and targeted attacks by identifying anomalies in outbound communications to C&C servers;
- Enable network protection layer to block exploits and drive-by attacks and contain the device from accessing enterprise resources when the risk is high.