back to article Forget Game of Thrones as Android ransomware infects TVs

Researchers at Trend Micro have spotted a new variant of ransomware code that can be used to lock down Android-powered smartphones and televisions. The FLocker (short for the Frantic Locker) malware has been in circulation since at least April 2015 and has concentrated on locking down smartphone handsets running the latest …

Page:

  1. redpawn

    Killing TVs, a step too far

    Infections happen to other peoples computers because they are not as smart as you, but the TV is sacred. If large numbers of TV/video service screens fall to malware expect a huge outcry and the demonizing of the affected brands. Might be enough to get regulators and manufacturers moving or at least pretending to move on security.

    1. FuzzyWuzzys

      Re: Killing TVs, a step too far

      My thoughts too. If this nasty piece of work and others that will no doubt come along, infect everyday devices then when average Joe Public gets pissed off that their new £6000 4K TV shuts down in the first week. If enough devices have to be returned, profits will be hit and then maybe we'll finally see the various manufacturers start to get some common sense when it comes to device security and stop trying to make everything easy at the expense of proper security.

      1. Seajay#

        Re: Killing TVs, a step too far

        What are you expecting the Manufacturers to do on security?

        This isn't a security hole in the TV / phone. You have to download this app, agree to install it, and agree to give it admin rights. Even after you've done all that it only locks the screen. What could the manufacturer possibly do to protect you from yourself in that scenario?

        1. Joe Bryant

          Re: Killing TVs, a step too far

          Maybe only apps that have passed some kind of safety check (and have a signature to prove it) could be allowed to have admin rights? That way, for example, only Samsung-certified apps are allowed to have admin rights on a Samsung TV.

        2. Dan 55 Silver badge

          Re: Killing TVs, a step too far

          What could the manufacturer do?

          a) Disable sideloading/fastboot/adb/etc... Although Kodi on a TV would be nice, I could live without it as the TV would just be another device to babysit.

          b) Include a reset pinhole. And let's face it, you need it with Android.

          1. Darren B 1

            Re: Killing TVs, a step too far

            I have an Android TV

            It does not allow Side Loading, no option to allow installing from unknown sources (which is a pain as I would like to install Amazon Prime Video),

            I installed ES FileExplorer and KODI as soon as I could from the Play Store.

            But have rarely use the Smart or Android features, just not compelling enough - I don't want to play Crossy Road or Candy Crush on a remote control and the Android Smartphone App for Android TV is poor on features (IIRC it was meant to act as a game pad but doesn't).

          2. Argh

            Re: Killing TVs, a step too far

            > What could the manufacturer do?

            > a) Disable sideloading/fastboot/adb/etc... Although Kodi on a TV would be nice, I could live without it as the TV would just be another device to babysit.

            You don't need sideloading/fastboo/adb/etc to run Kodi. It's on the Play store.

            > b) Include a reset pinhole. And let's face it, you need it with Android.

            Never needed it before and I've been with Android a long time. I have had to hold down the power button for a few seconds to force a shutdown though, I guess that's the same thing. The iPhone has the same feature though, with power button and home, and I know that's been needed a lot by friends.

            I don't know about Android TVs, but most (all?) Android phones can be wiped from the bootloader by holding a combination of buttons. I agree that some way of "factory resetting" a TV would be useful. My very old "Smart" TV (most smart functions no longer functioning, as it's so old and the services have changed) already has that on a menu, so I'd be quite surprised if it wasn't available on newer TVs.

          3. Roland6 Silver badge

            Re: Killing TVs, a step too far

            b) Include a reset pinhole. . And let's face it, you need it with Android.

            A pinhole reset is practically mandatory on any smart consumer gear and many business appliances such as routers, as it is the fastest way to return a device a known clean state and is an action the majority of people can perform when directed to do so by telephone support.

        3. DropBear

          Re: Killing TVs, a step too far

          "What could the manufacturer possibly do to protect you from yourself in that scenario?"

          Lots. For any supervisor "granting admin rights" is not equivalent to "I now wash my hands of al responsibilities you idiot". Even in the dumbest microcontroller, the first job of a proper bootloader is to protect itself by a) refusing to overwrite itself and b) provide a mechanism that makes it ALWAYS reachable. That's how you make an unbrickable device. By extension, a proper supervisor should have a mechanism that can always be reached when you need it allowing you to administer anything running on it - a task manager if you will. That would make killing / uninstalling this piece of garbage trivial...

          1. Phil O'Sophical Silver badge

            Re: Killing TVs, a step too far

            By extension, a proper supervisor should have a mechanism that can always be reached when you need it allowing you to administer anything running on it

            What is commonly known as "a backdoor", you mean? Yeah, that'll work.

        4. Doctor Syntax Silver badge

          Re: Killing TVs, a step too far

          "What could the manufacturer possibly do to protect you from yourself in that scenario?"

          Not make provision for apps to be given admin rights.

        5. PNGuinn
          Trollface

          "What are you expecting the Manufacturers to do on security?"

          It IS a bloody security hole. The tv is connected to the public sewer (internet) by design.

          What do you expect?

          Ah well, perhaps there's life in Norton for a while yet ....

          T'internet of 'fings don't you love it?

          Just wait till some scroat discovers how to stuff a payload into one of those loverly ads that are interspersed with those things called programmes ... or the other way round ....

        6. Flywheel

          Re: Killing TVs, a step too far

          Have you ever watched daytime TV and endured the ads for endless bingo and fruit/bling dropping games? Can you imagine the type of people that download this dross to understand the implications of allowing admin rights?

        7. Wade Burchette

          Re: Killing TVs, a step too far

          "What could the manufacturer possibly do to protect you from yourself in that scenario?"

          The solution is simple: sell TV's that only let you choose a source input or change the channel, like my first HDTV did. Roku, Apple TV, Fire TV, TiVo, etc do a much better job at streaming services than smart TV's anyway.

          1. goldcd

            Yep.

            It's not simply that they're better - they're better, you can upgrade them when they flag or take them with you to your next screen.

            Just noticed the other day that my nvidia shield thingie I plug into my TV is getting plex server support.

            Not client. Server.

            Sooo as well as feeding my TV screen, it'll be be able to transcode from my NAS and sync to my phone - no PC or TV requiring power.

        8. h4rm0ny

          Re: Killing TVs, a step too far

          >>" What could the manufacturer possibly do to protect you from yourself in that scenario?"

          In my case, sell me a TV that is a dumb output device. The lack of one available is why I don't currently own a 4K TV.

          As far as I'm concerned the words "Smart TV" translate as "something on my network that I can't patch, can't configure and for which proper support will probably be dropped within a year."

          1. Just Enough

            Re: Killing TVs, a step too far

            "As far as I'm concerned the words "Smart TV" translate as "something on my network that I can't patch, can't configure and for which proper support will probably be dropped within a year.""

            Last time I checked, a Smart TV is incapable of plugging in a network cable itself, or even attaching to your WiFi without the password. If it is on your network it is because you put it there. Do neither of these things and you have the "dumb output device" that you're looking for.

            1. Alumoi Silver badge

              Re: Killing TVs, a step too far

              "Last time I checked, a Smart TV is incapable of plugging in a network cable itself, or even attaching to your WiFi without the password. If it is on your network it is because you put it there. Do neither of these things and you have the "dumb output device" that you're looking for."

              Except for those smart asses... erm, TVs which refuse to allow you access to all the options unless you connect it to the network.

            2. Fitz_

              Re: Killing TVs, a step too far

              "Last time I checked, a Smart TV is incapable of plugging in a network cable itself, or even attaching to your WiFi without the password. If it is on your network it is because you put it there."

              I'm guessing you don't deploy anything within arms reach of users. Aside from that, many TVs are pretty useless when not on the network, particularly in enterprise environments where they will be used for information display etc.

            3. Anonymous Coward
              Anonymous Coward

              Re: Killing TVs, a step too far

              "Last time I checked, a Smart TV is incapable of plugging in a network cable itself, or even attaching to your WiFi without the password. If it is on your network it is because you put it there. Do neither of these things and you have the "dumb output device" that you're looking for."

              Except for the extended boot time (Android takes 30s-1min to boot after a proper power-off), delay on startup as it sits on the home screen scanning for network resources before letting you switch over to TV mode, and other such annoyances, etc (my "smart" TV has never been plugged into anything...). Would've bought a "dumb" TV if the "smart" ones hadn't had noticably better picture quality ...

          2. John H Woods Silver badge

            Re: Killing TVs, a step too far

            "In my case, sell me a TV that is a dumb output device. The lack of one available is why I don't currently own a 4K TV." -- h4rmony

            Mine too, but we're in the minority. But surely a discrete toggle switch to bypass all the smart components might be possible? Or one special HDMI socket that, when used, puts the machine in "monitor mode" with no functionality but picture controls?

            1. Boothy

              Re: Killing TVs, a step too far

              Quote: "But surely a discrete toggle switch to bypass all the smart components might be possible?"

              Why do you feel the need to bypass the smart stuff? It's not like it sits in-between anything!

              The smart part of a TV is basically just an App that you launch, don't want to use it, don't press the corresponding button on the remote (and like mentioned above, leave the network unconnected).

          3. Colin Ritchie
            Windows

            Re: Killing TVs, a step too far

            I'll be staying with a trusty, dumb TV and Humax box system until it dies and may consider a disposably cheap Chromecast as a replacement when it does. A Moto G can then do the heavy lifting and I can keep that secure myself... I think.

        9. Omar Smith

          Re: Killing TVs, a step too far

          > This isn't a security hole in the TV / phone.

          So this headline is misleading "Android ransomware infects TVs" else it would be ransomware infects peoples brains :)

        10. Fungus Bob

          Re: Killing TVs, a step too far

          "What could the manufacturer possibly do to protect you from yourself in that scenario?"

          They could sell you an Etch-A-Sketch instead of a TV pretending to be a phone.

    2. Anonymous Coward
      Anonymous Coward

      Re: Killing TVs, a step too far

      Don't worry, it's not real.....

      "After the malware file is downloaded via an infected website or SMS file,"

      You really have to try very hard indeed to get this on your TV or phone, you actually have to disable onboard security mechanisms before you even get to bring affected by this.

      Oops, did they conveniently forget to mention this? How forgetful of them....

  2. Paratrooping Parrot
    Mushroom

    This is the future of IoT

    We are all doomed! Trying to get everything to install applications from the Internet is a disaster waiting to happen!

    1. Pascal Monett Silver badge

      Apparently it is a disaster that is happening now. No waiting needed.

      Personally I'm quite happy about all this. IoT is snake oil, made by ignorant companies forcing coders to do insane things without ever thinking about consequences.

      The quicker the fecal matter hits the wildly spinning distribution apparatus, the quicker the whole thing will get shot in the leg to hobble off to the landfill where it belongs.

      Then, maybe, we'll have a second generation of IoT that will a) actually be useful and b) be carefully thought out, thoroughly tested and tried IRL before getting sold on the open market.

      This is not IT. The excuse that people are not savvy enough to understand what admin rights mean does not apply. This is people buying a fridge to replace a fridge, then finding out that it connected wirelessly and ordered a thousand gallons of milk because bug.

      Nobody can go to court over an encrypted drive. You cry and eat the loss. But that ? They will be royally pissed about it, and have the goods to go to court. Having an EULA stating that the maker is not responsible for any loss of product will not stand in court, you can bet on that.

      This will end in tears, mark my words.

  3. graeme leggett Silver badge

    geographic preference

    I wonder if we can discern anything about the malware creators from that...

    1. Voland's right hand Silver badge

      Re: geographic preference

      Do not think so.

      That looks like a list of countries where there is no chance in hell someone to Joe Average to pay that amount of money. Instead of paying, the victim will go to the kid next door which will sort it out and post the cleanup howto somewhere on the interwebs

      Most malware writers are pragmatists, they do not want to create a situation where the information on how to get rid of their handywork is readily available.

      1. Anonymous Coward
        Anonymous Coward

        Ré Re: geographic preference

        Rowlocks.

        There are PLENTY of countries far poorer than those named; either these contain his home territory, or he is afraid the locals will take out a contract on him.

        (We are far too nice to these people).

    2. Oengus

      Re: geographic preference

      Simple... They don't want their family members getting them to try and fix their borked devices because they are the "family tech expert".

  4. stu 4

    User???

    "Users can connect their device with a PC and launch the ADB shell and execute the command 'PM clear %pkg%.'

    Since when is someone with a TV a 'user'... and WTF chance does the standard unwashed viewer have of doing this ?

    1. Law

      Re: User???

      If think they're smart enough to enable 3rd party applications, download a dodgy all, and then dumb enough to grant his random apk admin rights to the TVs android OS... then they aren't the unwashed masses.

      They're either one of two types of people... an idiot who thinks they're smart, or an idiot who thinks fellow pirates on a forum are smart enough to trust.

      Fyi... I'm one of these people who enable 3rd party apps on their android streaming device... they're Amazon fire TV boxes, I installed kodi (used their stable build from their site) via adb, then disabled 3rd party option again to lock it all back down. My only issue is I can't lock down updates from Amazon to stop the ads creep that's been slowly ruining my experience over the last year and a half.

  5. Anonymous Coward
    Anonymous Coward

    Yet another reason to skip Smart TV:

    S.M.A.R.T:

    Slurping Marketed as Revolutionary Technology...

    ....

    Surveillance Marketed as Revolutionary Technology...

    1. Anonymous Coward
      Anonymous Coward

      Re: Yet another reason to skip Smart TV:

      @AC - Software Mucking up A Real TV?

  6. werdsmith Silver badge

    Shopping for TVs the other day, the "sales" guy pointed out a range of TVs with Android TV on.

    Me: "very nice, now I know which ones to avoid, what else have you got".

    1. Dave 126 Silver badge

      All the Sony TVs have Android built in, and they make some of the best LED TVs, along with Samsung who use their own Tizen OS.

      LG, who are the only ones making OLED tvs, use WebOS.

      LED sets are brighter, so perhaps more suitable for watching in well lit situations, OLED sets have perfectly black blacks, making them better for watching movies with the lights down.

      You won't be able to buy a 'dumb screen' at a TV sizes, but nobody is forcing you to plug an ethernet cable into it. By the time 4K content is more widely available, external HDMI 2.0 boxes should be cheaper.

      1. werdsmith Silver badge

        I've no problem plugging a cable or connecting the TV by WiFi, it's just Android which is the turn off.

        And as for blacker blacks and analling over picture quality detail, I really can't be bothered. On the latest TVs there is barely a difference worth worrying about.

      2. Known Hero
        Thumb Up

        About 1 year ago I managed to buy a 50" dumb TV.

        My priorities were

        1.Non Smart

        2.Quality

        3.Size

        just saying it can still be done :)

        1. Dave 126 Silver badge

          If you don't want a connected TV, don't connect it to your network.

          Similarly: If you don't want your TV to pick up terrestrial broadcasts, don't plug in an aerial.

          For smaller sizes, you could just buy yourself a monitor I guess, but at bigger sizes every TV using the latest panel technology (OLED, Quantum Dot, local dimming etc) will have a 'smart' functionality and a tuner or two. The functionality really doesn't add much to the cost of the TV.

          1. Cameron Colley

            @Dave126

            What if it connects to the neighbour's network? Or somebody walking past? When you can't tell whether the "smart" part is switched on how do you know whether it's trying to download the latest Android update or worse?

            As for broadcast TV, in the UK owning a TV with a tuner may mean having to rip out an old antenna cable and the hassles to go with it as well as making it harder to deny to the TV Licensing Stasi that you don't watch TV.

            What a lot of us want are dumb screens (with some decently-powered USB power ports, perhaps) to plug things into. But, sadly, that doesn't sound flash enough for marketing so this shite is wheeled out instead.

            1. Dave 126 Silver badge

              Re: @Dave126

              >What if it connects to the neighbour's network? Or somebody walking past?

              Android TVs don't do that! Stop plucking bullshit out of the air, FFS!

              There is nothing stopping you from using these TVs as dumb screens - just don't connect them to the fucking network if you don't want to. It. Really. Is. That. Simple.

              >But, sadly, that doesn't sound flash enough for marketing so this shite is wheeled out instead.

              This 'shite' (iPlayer et al) is useful for many people and adds less than tenner for the bill of materials on a £400+ television, if that.

              1. Anonymous Coward
                Anonymous Coward

                "just don't connect them to the network"....

                ....Assumptions... The mother of all fuckups...

                ...1. Some Smart TV's disable features if you don't let them phone home. This is well documented. Past Reg articles have covered this with posters likening it to Overton-Window syndrome...

                ...2. At a residents meeting last year, we learned that a rogue kid in the area had connected several neighbours TV's to the net! It was 6 months before it was discovered...

                ...3. Android TV's don't hunt for open connections... More assumption making... No one expected LG to log the names of USB files opened on their smart TV's, yet they did! Manufacturers are far more desperate than many realize as margins have vanished.

                ...4. Buyers don't want to pay an extra premium for Smart, when the extra chipsets aren't needed. Everyone wants the best deals, but Smart costs more. So manufacturers have offset this by choosing to monetize consumers later on. What do you think will happen if sufficient consumers don't connect... Prices will go up or down...???

              2. Cameron Colley

                Re: @Dave126

                So, Dave126, you know for certain that no manufacturer has ever, no will ever, either intentionally nor accidentally allow the device to attempt to automatically connect to wireless networks?

                I'm glad there's an Android developer who works for all major manufacturers on this site, thanks Dave126 for clearing that up...

  7. Chris G

    Aahh!

    The baby IoT is having teething problems.

    Best to kill the bastard child now before it grows into a monster.

    Next step for all things IoT will be buy the thing, buy extended warranty, buy some new form of anti malware to go with it and finally for most people a service agreement so that a man can keep the updates updated.

    1. Dave 126 Silver badge

      Re: Aahh!

      Modern TVs come with a 5 year guarantee as standard, in keeping with our statuary right to have it last a 'reasonable' time.

      1. waldo kitty
        Facepalm

        Re: Aahh!

        Modern TVs come with a 5 year guarantee as standard, in keeping with our statuary right to have it last a 'reasonable' time.

        5 years is no where near any sort of "reasonable time". 10 years, sure. 15? Yup. 20? Definitely. Are people really so stupid that their being "nickled and dimed" is now at the level of hundreds or thousands of $$$?

        What I really want to know is "How is the user going to fix this problem when they don't even have a PC any more?" In their grand ignorance and desire for total convenience, they've all switched to those so-called smart phone things which are very likely to be vulnerable to this infectious mess. Can you hear the Luddites laughing?

        1. Dave 126 Silver badge

          Re: Aahh!

          'Reasonable time' is the phrase arrived at by our elected representatives, not the TV vendors. Five years is not the mean time before failure, either. Nothing is stopping you from making a case to Trading Standards if your TV fails after seven years - five years is merely a figure that the vendors are using, and what they offer has no effect on your statutory rights. However, what is 'reasonable' depends upon the product.

          If you really have an issue with it, write to your MP.

          People don't see themselves as being 'nickle and dimed' when the television they can buy for £500 today is far bigger and of higher resolution than a set the same money would have bought them a few years back. Oh, and don't suggest the general public are 'stupid' - it betrays your ignorance.

          >What I really want to know is "How is the user going to fix this problem when they don't even have a PC any more?"

          Well, if the product proves to be 'not fit for the purpose for which it was sold', the onus is on the retailer to sort the issue out for the buyer

          1. waldo kitty
            Boffin

            Re: Aahh!

            If you really have an issue with it, write to your MP.

            Apparently you think I live in the UK. I do not ;)

Page:

POST COMMENT House rules

Not a member of The Register? Create a new account here.

  • Enter your comment

  • Add an icon

Anonymous cowards cannot choose their icon

Other stories you might like