Qihoo 360 Protects against Recently Discovered Android Vulnerability

Jul 10, 2013, 08:00 ET from Qihoo 360 Technology Co. Ltd.

BEIJING, July 10, 2013 /PRNewswire/ -- Qihoo 360 (NYSE: QIHU), a leading Internet security company in China, today published an updated version of its mobile security app that protects users from mobile threats caused by a serious system vulnerability recently discovered in the Android operating system. Researchers believe that this vulnerability, which is believed to be prevalent in devices using Android 1.6 and later, could place nearly 99% of Android-based devices at risk.

After an in-depth analysis of the principal attack schema of the vulnerability, Qihoo 360's security experts found that malware developers can insert malicious code into a legitimate Android Application Package ("APK") without breaking its digital signature. This enables the application to bypass Android's built-in signature verification mechanisms to launch a variety of malicious functions.

Through this process, hackers can trick users to install repackaged APKs with malicious updates and therefore control the infected phones and collect users' contact lists, SMS and call logs, login information and other private data. This vulnerability could give hackers full control over an infected device, allowing them to use dialing/texting functions and activate the camera without the user's knowledge or permission.

Starting on July 9, Beijing time, Qihoo 360's security experts noticed that the exploitation code of this vulnerability has been spread over several technical forums. While Google has already taken measures to protect applications in the Google Play store and provided a patch to handset manufacturers, many handsets and third party app stores have not yet implemented the security update and are not yet protected.

Recognizing the potential damaging impact for our users, Qihoo 360 has prepared and released an updated version of 360 Mobile Security to better protect its users with proactive alerts and necessary warnings. In addition, Qihoo 360 strongly recommends users to download or run apps only from trusted sources, such as Google Play and 360 Mobile Assistance.

(360 Mobile Security: https://play.google.com/store/apps/details?id=com.qihoo.security)

About Qihoo 360

Qihoo 360 Technology Co. Ltd. (NYSE: QIHU) is a leading Internet company in China. The Company is also the number one provider of Internet and mobile security products in China as measured by its user base, according to iResearch. Qihoo 360 also provides users with secure access points to the Internet via its market leading web browsers and application stores. The Company has built one of the largest open Internet platforms in China and monetizes its massive user base primarily through online advertising and through Internet value-added services on its open platform.

SOURCE Qihoo 360 Technology Co. Ltd.