1. AC Question's Avatar
    Recently, I have had a friend with a new Galaxy S7 that has been infected by some sort of persistent exploit/hack. Seemingly randomly, the device will start typing, launch random applications, and even start the camera up.
    My first thought was that it was infected by a piece of malware so I ran a variety of scans that came up with nothing. I figured if I reset his phone and did a full factory reset that it would wipe the phone clear and he would be good to go, but this did not work. A day or so later (he had not downloaded any apps, just kept the stock ones - and no internet browsing through chrome etc..) the phone started launching apps and the camera etc while he was using it...
    I figured at this point it must be a persistent piece of software implanted in the actual OS that survive the factory reset that used a reverse tcp attack. This means it would survive a factory reset and then would send a packet to connect to the hackers computer at random times giving the hacker a notification of a new session and full access (probably using metasploit). I used Wireshark (a network packet capturing software) to monitor his phone and packets for any connections the phone tried to make with an external ip address - other than the google services and servers - but nothing registered. Odd. Did a factory reset again and signed in with a brand new Google account.
    Fast forward a few days and his phone started doing the same thing again - only this time his data and wifi were completely off. However, it acted as if it was being controlled externally.

    The only thing I can think of now is that it is being exploited by a media messages via a text message? There have been reports in the past about Android phones being exploited by specially crafted media messages.

    Any thoughts about what this might be/how to get rid of it?
    05-26-2016 04:05 PM
  2. Rukbat's Avatar
    Reflash the ROM (you'll have to back everything up first - reflashing the ROM gives you an out-of-the-box phone).
    05-26-2016 07:20 PM

Similar Threads

  1. Is it Worth Buying a New G4 Today?
    By richv77 in forum LG G4
    Replies: 24
    Last Post: 06-11-2016, 05:51 AM
  2. Help stuck in android recovery mode on htc m8
    By bengben in forum HTC One M8
    Replies: 2
    Last Post: 05-28-2016, 12:22 AM
  3. Replies: 2
    Last Post: 05-26-2016, 06:57 PM
  4. S7 says its connected to a USB
    By infiCathi in forum Samsung Galaxy S7
    Replies: 1
    Last Post: 05-26-2016, 05:59 PM
  5. Wireless charging when using Android Auto
    By jalan94 in forum Android Auto
    Replies: 1
    Last Post: 05-26-2016, 04:19 PM