Alert level

Exploit:Unix/Lotoor

(?)

Encyclopedia entry
Updated: Mar 15, 2012  |  Published: Mar 12, 2011

Aliases
  • Android.DreamExploid.1 (Dr.Web)
  • Exploit.Linux.Lotoor.l (Kaspersky)
  • Backdoor.AndroidOS.Rooter.a (Kaspersky)
  • Android/DNightmare (McAfee)
  • Troj/DroidD-A (Sophos)
  • Android.Rootcager (Symantec)
  • rageagainstthecage (other)
  • exploid (other)

Alert Level (?)
Severe

Antimalware protection details
Microsoft recommends that you download the latest definitions to get protected.
Detection last updated:
Definition: 1.113.1022.0
Released: Oct 05, 2011
Detection initially created:
Definition: 1.99.460.0
Released: Mar 02, 2011


 

Summary

Exploit:Unix/Lotoor is a detection for specially-crafted Android programs that attempt to exploit vulnerabilities in the Android operating system to gain root privileges.



 

Symptoms

There are no common symptoms associated with this threat. Alert notifications from installed antivirus software may be the only symptoms.


 

Technical Information (Analysis)

Exploit:Unix/Lotoor is a detection for specially-crafted Android programs that attempt to exploit vulnerabilities in the Android operating system to gain root privileges.

Payload

Allows root access

When run, Exploit:Unix/Lotoor allow a remote attacker to gain administrator privilege on a device running the Android operation system.

Additional information

Exploit:Unix/Lotoor has been known to be dropped and installed by TrojanSpy:AndroidOS/DroidDream.A. Once installed, the exploit may be present in the mobile device with the following names:

  • rageagainstthecage
  • exploid

Analysis by Tim Liu



 

Prevention



 

Recovery

Install security software on your device
This malware affects mobile devices. Additional information on how to attain security software for your mobile device can be found here: http://www.microsoft.com/windowsmobile/en-us/totalaccess/columns/mobile-security.mspx

Provide feedback