Jump to content

Android Emulator for PC "Andy Android" found including Cryptominer Trojan

rcmaehl

Sources

https://betanews.com/2018/06/18/andy-os-bitcoin-miner/

https://www.bleepingcomputer.com/news/security/andy-os-android-emulator-reportedly-installing-a-gpu-miner/


From the Sources:

Quote

Cryptocurrency mining malware has become a serious problem recently, and it seems the latest people to fall victim to the threat are users of the Android emulator Andy OS -- also referred to as AndY and Andyroid. ...

Over on Bleeping Computer, Lawrence Abrams did a bit of investigating. He noted that even when declining all of the bundled adware offered up by Andy's installer, it seemed that the miner was installed. He also notes that VirusTotal has marked the installer as an InstallCore variant with various warnings attached to it, and that the updater.exe file is detected as a cryptocurrency miner.

 

Quote

...This GoogleUpdate.exe program has a description of "AndyOS Update", which indicates it's part of Andy. Why it is named GoogleUpdate is not known, but I feel it is strange. ... As the GoogleUpdate.exe is signed using a signature that is owned by Andy OS Inc, it would indicate that this file it one that belongs to them.


Video of the issue:

 

My thoughts:
It seems like yet again. Developers of Android Emulators for Windows have gotten greedy. Alternatives exist but the large number of ones engaged in scummy tactics such as this or those that include bundled apps and paid versions use their questionably obtained money to ensure they become the top search results instead of open sourced projects.

PLEASE QUOTE ME IF YOU ARE REPLYING TO ME

Desktop Build: Ryzen 7 2700X @ 4.0GHz, AsRock Fatal1ty X370 Professional Gaming, 48GB Corsair DDR4 @ 3000MHz, RX5700 XT 8GB Sapphire Nitro+, Benq XL2730 1440p 144Hz FS

Retro Build: Intel Pentium III @ 500 MHz, Dell Optiplex G1 Full AT Tower, 768MB SDRAM @ 133MHz, Integrated Graphics, Generic 1024x768 60Hz Monitor


 

Link to comment
Share on other sites

Link to post
Share on other sites

49 minutes ago, VegetableStu said:

on one hand, I really hate it when people squat on my PC processor time.

 

on the other, we should tip jar people who posts pretty functional stuff that we use once in a while.

Tips are entirely voluntary, however. If a developer asks (for example, when installing) for contributions to be made via mining, I wouldn't have a problem. Laptop users can keep it disabled to conserve battery, and desktop users can contribute to the developer.

My eyes see the past…

My camera lens sees the present…

Link to comment
Share on other sites

Link to post
Share on other sites

3 minutes ago, Zodiark1593 said:

Tips are entirely voluntary, however. If a developer asks (for example, when installing) for contributions to be made via mining, I wouldn't have a problem. Laptop users can keep it disabled to conserve battery, and desktop users can contribute to the developer.

The concept is okay but permission should be given first. Naming the process GoogleUpdate.exe just indicates that they did not want anyone to link it to the program which generally indicates malicious intent - what it to stop them next installing a keylogger and selling the results for "personalization" of "advertisements".

Link to comment
Share on other sites

Link to post
Share on other sites

I looked heavily into them a year ago. I don't find this remotely shocking, the people behind it gave off huge red flags.

Come Bloody Angel

Break off your chains

And look what I've found in the dirt.

 

Pale battered body

Seems she was struggling

Something is wrong with this world.

 

Fierce Bloody Angel

The blood is on your hands

Why did you come to this world?

 

Everybody turns to dust.

 

Everybody turns to dust.

 

The blood is on your hands.

 

The blood is on your hands!

 

Pyo.

Link to comment
Share on other sites

Link to post
Share on other sites

Minimum requirements is Windows 7, has a picture of Windows XP on their main page. Quality. Also why does it have a Mac OSX themed window?

image.png.0ef45b7751ee015485a97cb05ad25572.png

Intel® Core™ i7-12700 | GIGABYTE B660 AORUS MASTER DDR4 | Gigabyte Radeon™ RX 6650 XT Gaming OC | 32GB Corsair Vengeance® RGB Pro SL DDR4 | Samsung 990 Pro 1TB | WD Green 1.5TB | Windows 11 Pro | NZXT H510 Flow White
Sony MDR-V250 | GNT-500 | Logitech G610 Orion Brown | Logitech G402 | Samsung C27JG5 | ASUS ProArt PA238QR
iPhone 12 Mini (iOS 17.2.1) | iPhone XR (iOS 17.2.1) | iPad Mini (iOS 9.3.5) | KZ AZ09 Pro x KZ ZSN Pro X | Sennheiser HD450bt
Intel® Core™ i7-1265U | Kioxia KBG50ZNV512G | 16GB DDR4 | Windows 11 Enterprise | HP EliteBook 650 G9
Intel® Core™ i5-8520U | WD Blue M.2 250GB | 1TB Seagate FireCuda | 16GB DDR4 | Windows 11 Home | ASUS Vivobook 15 
Intel® Core™ i7-3520M | GT 630M | 16 GB Corsair Vengeance® DDR3 |
Samsung 850 EVO 250GB | macOS Catalina | Lenovo IdeaPad P580

Link to comment
Share on other sites

Link to post
Share on other sites

Why don't people just use a virtual Android x86? Is that project dead or something?

Link to comment
Share on other sites

Link to post
Share on other sites

1 minute ago, RorzNZ said:

Why don't people just use a virtual Android x86? Is that project dead or something?

Project is going strong, but virtualized, Android x86 is a shit show with KB+M.

Come Bloody Angel

Break off your chains

And look what I've found in the dirt.

 

Pale battered body

Seems she was struggling

Something is wrong with this world.

 

Fierce Bloody Angel

The blood is on your hands

Why did you come to this world?

 

Everybody turns to dust.

 

Everybody turns to dust.

 

The blood is on your hands.

 

The blood is on your hands!

 

Pyo.

Link to comment
Share on other sites

Link to post
Share on other sites

2 minutes ago, Drak3 said:

Project is going strong, but virtualized, Android x86 is a shit show with KB+M.

Like it's not as if it needs a lot of power to run Android lol. I see the problem with KB&M though, it's always going to be much better with touchscreen. 

Link to comment
Share on other sites

Link to post
Share on other sites

Just now, RorzNZ said:

Like it's not as if it needs a lot of power to run Android lol. I see the problem with KB&M though, it's always going to be much better with touchscreen. 

KB+M works well when running on bare metal, especially with a good launcher.

 

But virtualized, the mouse acts like a finger. If you're not holding down the LMB, it acts as if you're not interacting with it, but still shows a cursor.

Come Bloody Angel

Break off your chains

And look what I've found in the dirt.

 

Pale battered body

Seems she was struggling

Something is wrong with this world.

 

Fierce Bloody Angel

The blood is on your hands

Why did you come to this world?

 

Everybody turns to dust.

 

Everybody turns to dust.

 

The blood is on your hands.

 

The blood is on your hands!

 

Pyo.

Link to comment
Share on other sites

Link to post
Share on other sites

6 hours ago, Drak3 said:

Project is going strong, but virtualized, Android x86 is a shit show with KB+M.

No love for Blustacks ?

 Motherboard  ROG Strix B350-F Gaming | CPU Ryzen 5 1600 | GPU Sapphire Radeon RX 480 Nitro+ OC  | RAM Corsair Vengeance DDR4 3000MHz 2x8Gb | OS Drive  Crucial MX300 525Gb M.2 | WiFi Card  ASUS PCE-AC68 | Case Switch 810 Gunmetal Grey SE | Storage WD 1.5tb, SanDisk Ultra 3D 500Gb, Samsung 840 EVO 120Gb | NAS Solution Synology 413j 8TB (6TB with 2TB redundancy using Synology Hybrid RAID) | Keyboard SteelSeries APEX | Mouse Razer Naga MMO Edition Green | Fan Controller Sentry LXE | Screens Sony 43" TV | Sound Logitech 5.1 X530

Link to comment
Share on other sites

Link to post
Share on other sites

1 minute ago, Noctus said:

No love for Blustacks ?

Bluestacks runs like shit on my 5930K @4.5GHz, 32GB DDR4-2133, and 1080. It went about 10 minutes before I uninstalled it due to frustration. I can't recommend it (or any other method of virtualizing Android).

 

The only thing I haven't tried is Android x86 in KVM, I don't have a machine I'm willing to sacrifice to KVM right now.

Come Bloody Angel

Break off your chains

And look what I've found in the dirt.

 

Pale battered body

Seems she was struggling

Something is wrong with this world.

 

Fierce Bloody Angel

The blood is on your hands

Why did you come to this world?

 

Everybody turns to dust.

 

Everybody turns to dust.

 

The blood is on your hands.

 

The blood is on your hands!

 

Pyo.

Link to comment
Share on other sites

Link to post
Share on other sites

2 minutes ago, Drak3 said:

Bluestacks runs like shit on my 5930K @4.5GHz, 32GB DDR4-2133, and 1080. It went about 10 minutes before I uninstalled it due to frustration. I can't recommend it (or any other method of virtualizing Android).

 

The only thing I haven't tried is Android x86 in KVM, I don't have a machine I'm willing to sacrifice to KVM right now.

Very odd considering my Ryzen 5 1600 (standard clocked), 16gig DDR4-3000 and a RX 480 run it just fine .... o.0

 Motherboard  ROG Strix B350-F Gaming | CPU Ryzen 5 1600 | GPU Sapphire Radeon RX 480 Nitro+ OC  | RAM Corsair Vengeance DDR4 3000MHz 2x8Gb | OS Drive  Crucial MX300 525Gb M.2 | WiFi Card  ASUS PCE-AC68 | Case Switch 810 Gunmetal Grey SE | Storage WD 1.5tb, SanDisk Ultra 3D 500Gb, Samsung 840 EVO 120Gb | NAS Solution Synology 413j 8TB (6TB with 2TB redundancy using Synology Hybrid RAID) | Keyboard SteelSeries APEX | Mouse Razer Naga MMO Edition Green | Fan Controller Sentry LXE | Screens Sony 43" TV | Sound Logitech 5.1 X530

Link to comment
Share on other sites

Link to post
Share on other sites

Just now, Noctus said:

Very odd considering my Ryzen 5 1600 (standard clocked), 16gig DDR4-3000 and a RX 480 run it just fine .... o.0

Wouldn't know, Ryzen wasn't announced the last time I bothered with it. I basically gave up on virtualizing Android in any capacity. I'd rather recommend buying a cheap Core i ANYTHING 2-in-1 with a SSD and putting Android x86 on it.

Come Bloody Angel

Break off your chains

And look what I've found in the dirt.

 

Pale battered body

Seems she was struggling

Something is wrong with this world.

 

Fierce Bloody Angel

The blood is on your hands

Why did you come to this world?

 

Everybody turns to dust.

 

Everybody turns to dust.

 

The blood is on your hands.

 

The blood is on your hands!

 

Pyo.

Link to comment
Share on other sites

Link to post
Share on other sites

This is why you should use a VM and emulate Android x86, it might not look pretty but works perfectly and that's what matters here, even dared to install it in a real partition and everything worked, git gud andy.

ASUS X470-PRO • R7 1700 4GHz • Corsair H110i GT P/P • 2x MSI RX 480 8G • Corsair DP 2x8 @3466 • EVGA 750 G2 • Corsair 730T • Crucial MX500 250GB • WD 4TB

Link to comment
Share on other sites

Link to post
Share on other sites

1 hour ago, Drak3 said:

Bluestacks runs like shit on my 5930K @4.5GHz, 32GB DDR4-2133, and 1080. It went about 10 minutes before I uninstalled it due to frustration. I can't recommend it (or any other method of virtualizing Android).

 

The only thing I haven't tried is Android x86 in KVM, I don't have a machine I'm willing to sacrifice to KVM right now.

 

1 hour ago, Noctus said:

Very odd considering my Ryzen 5 1600 (standard clocked), 16gig DDR4-3000 and a RX 480 run it just fine .... o.0

I think blustacks is hit and miss,  My son ran it fine on his pentium 2 core with 8G ram and still fine when we upgraded it  to a ryzen 3 1200.  By other son runs his fine on an older i3 with 8G ram also.

Grammar and spelling is not indicative of intelligence/knowledge.  Not having the same opinion does not always mean lack of understanding.  

Link to comment
Share on other sites

Link to post
Share on other sites

13 hours ago, Zodiark1593 said:

Tips are entirely voluntary, however. If a developer asks (for example, when installing) for contributions to be made via mining, I wouldn't have a problem. Laptop users can keep it disabled to conserve battery, and desktop users can contribute to the developer.

Somehow WinRar is still around and they only ask politely to be paid.

 

Shame the devs includes this; asking like WinRar might actually be a valid option here. It’s a tip or donation; and doesn’t negatively affect your users.

 

 

5950X | NH D15S | 64GB 3200Mhz | RTX 3090 | ASUS PG348Q+MG278Q

 

Link to comment
Share on other sites

Link to post
Share on other sites

I was recently using AndyOS just to mess around with Android on PC - experience was extremely *insert a profanity here for bad* on my 6800K and 1070.
What I do like is what has been put in the description of the video:

Quote

made this for the people in the andy support group. got banned :(

So, it looks like when it was reported to the Andy team, they are just like - "Screw You, we don't like you've found us out so...You're banned."

VOY6mtb.png
If that doesn't scream shady - we need to get Slim in the house to do it, because this is shady AF.  

Ryze of the Phoenix: 
CPU:      AMD Ryzen 5 3600 @ 4.15GHz
Ram:      64GB Corsair Vengeance LPX DDR4 @ 3200Mhz (Samsung B-Die & Nanya Technology)
GPU:      MSI RTX 3060 12GB Aero ITX
Storage: Crucial P3 1TB NVMe Gen 4 SSD, 1TB Crucial MX500, Spinning Rust (7TB Internal, 16TB External - All in-use),
PSU:      Cooler Master MWE Gold 750w V2 PSU (Thanks LTT PSU Tier List)
Cooler:   BeQuite! Prue Rock 2 Black Edition
Case:     ThermalTake Versa J22 TG

Passmark 10 Score: 6096.4         CPU-z Score: 4189 MT         Unigine Valley (DX11 @1080p Ultra): 5145         CryEngine Neon Noir (1080p Ultra): 9579

Audio Setup:                  Scarlett 2i2, AudioTechnica AT2020 XLR, Mackie CR3 Monitors, Sennheiser HD559 headphones, HyperX Cloud II Headset, KZ ES4 IEM (Cyan)

Laptop:                            MacBook Pro 2017 (Intel i5 7360U, 8GB DDR3, 128GB SSD, 2x Thunderbolt 3 Ports - No Touch Bar) Catalina & Boot Camp Win10 Pro

Primary Phone:               Xiaomi Mi 11T Pro 5G 256GB (Snapdragon 888)

Link to comment
Share on other sites

Link to post
Share on other sites

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now

×