Cyber Security News

Pandora Malware Attacks Android TVs via Firmware Updates and Pirated Videos

A new threat to Android devices named android[.]pandora has been identified that compromises the devices when pirated video content is installed or during firmware updates.

This malware belongs to the variant of Mirai Trojan, which has been used to infect smart devices and utilize a network of remotely controlled bots or “zombies” to launch DDOS.

Doctor Web has identified this malware as Android.Pandora.10 and its capabilities and shared the detailed report on its official page.

This malware targets users of Android TV-based devices with lower prices, especially users of the Tanix TX6 TV Box, MX10 Pro 6K, and H96 MAX X3.

Once the machine gets infected, it changes the files in the system directory, and the below objects have been installed to launch the trojan 

  • /system/bin/pandoraspearrk
  • /system/bin/supervisord
  • /system/bin/s.conf
  • /system/xbin/busybox
  • /system/bin/curl

Pandoraspearrk – Identified in the virus database as the Android[.]Pandora[.]2 backdoors and used to perform DDoS.

The supervisord – monitors the status of the pandoraspearrk executable and restarts the backdoor if it is terminated.

s.conf – stored the settings for Supervisord 

The busybox and curl command-line utilities with the same name are included for networking and file system operations.

This malware can be installed as part of a firmware update available for download on several places as Android Open Source Project test keys.

Installing pirated movie and TV apps is an alternative way malware invades Android devices.     

Once launched successfully, the device’s malicious programs can interact with open ports.

The backdoor downloads a host’s file to replace the original system file, starts the self-update process and becomes ready to receive commands.

By sending commands to an infected device, attackers can launch and stop DDoS attacks over the TCP and UDP protocols, perform SYN, ICMP, and DNS flood, open a reverse shell, mount Android TV system partitions in read/write mode, and so on. 

Keep informed about the latest Cyber Security News by following us on Google NewsLinkedinTwitter, and Facebook.

Sujatha

Sujatha is a Cyber security content editor with a passion for creating captivating and informative content. With years of experience under her belt in Cyber Security, she is covering Cyber Security News, technology and other news.

Recent Posts

Hackers Target AI Infrastructure With RCE, Prompt Injection and API Key Theft

Hackers are actively probing AI systems, turning exposed gateways and agent tools into routes for…

4 hours ago

Hackers Make Phishing Pages Change Their Code Every Time Someone Opens Them

Hackers are making some phishing pages harder to track by changing the code delivered to…

4 hours ago

Iran-Linked Hackers Reportedly Knock UK Power Plant Offline for Four Days

A cyber incident reportedly forced a British power plant to halt operations for about four…

5 hours ago

Russian Hackers Use New HOOKEDGE Malware to Spy on European Defense and Diplomatic Targets

Russian hackers have used a new backdoor called HOOKEDGE to target defense manufacturers, government bodies,…

6 hours ago

Ransomware Gang Claims AI Can Analyze 700GB of Stolen Data Every Hour

TITAN ransomware is pairing file encryption with an ambitious claim: artificial intelligence that can sort…

6 hours ago

Hackers Compromise Hundreds of WordPress Sites to Deploy Amatera Stealer via ClickFix

A fake student resume is being used to place a remote-access tool on researchers’ Windows…

7 hours ago