Fotolia

Com.google.provision virus: How does it attack Android devices?

The com.google.provision virus reportedly targets Android users, but little is known about it. Nick Lewis discusses the mystery threat and how Common Malware Enumeration may help.

What is the com.google.provision virus? How does it attack Android devices?

It's difficult to look up a virus when its name is unknown. For vulnerabilities, this issue was addressed with Common Vulnerabilities and Exposures, and for malware, it was dealt with using Common Malware Enumeration (CME) identifiers.

Enterprise information security programs would benefit from tracking vulnerabilities or malware across an enterprise; however, this remains difficult as CME development continues.

This problem is evident today with the com.google.provision virus. Several websites reported the virus, but only a few major antimalware vendors did. This could be because other vendors called it by a different name, or because it wasn't deemed a high enough risk to devote resources to a public comment.

Several websites discuss the com.google.provision virus being used to display ads on infected systems, and that it could be an installed application, web browser extension or a malicious JavaScript exploiting insecure functionality in a web browser to display ads.

The attack seems to work like generic adware in the sense that, when visiting a malicious website, the website opens a new window that displays ads, and then asks the user to install a browser extension, to install applications to view the webpage or even to clean up a problem, such as fake antivirus software scams.

Ask the expert:
Have a question about enterprise threats? Send it via email today. (All questions are anonymous.)

Dig Deeper on Threats and vulnerabilities

Networking
CIO
Enterprise Desktop
  • Understanding how GPOs and Intune interact

    Group Policy and Microsoft Intune are both mature device management technologies with enterprise use cases. IT should know how to...

  • Comparing MSI vs. MSIX

    While MSI was the preferred method for distributing enterprise applications for decades, the MSIX format promises to improve upon...

  • How to install MSIX and msixbundle

    IT admins should know that one of the simplest ways to deploy Windows applications across a fleet of managed desktops is with an ...

Cloud Computing
ComputerWeekly.com
Close