What is the com.google.provision virus? How does it attack Android devices?
It's difficult to look up a virus when its name is unknown. For vulnerabilities, this issue was addressed with Common Vulnerabilities and Exposures, and for malware, it was dealt with using Common Malware Enumeration (CME) identifiers.
Enterprise information security programs would benefit from tracking vulnerabilities or malware across an enterprise; however, this remains difficult as CME development continues.
This problem is evident today with the com.google.provision virus. Several websites reported the virus, but only a few major antimalware vendors did. This could be because other vendors called it by a different name, or because it wasn't deemed a high enough risk to devote resources to a public comment.
The attack seems to work like generic adware in the sense that, when visiting a malicious website, the website opens a new window that displays ads, and then asks the user to install a browser extension, to install applications to view the webpage or even to clean up a problem, such as fake antivirus software scams.
Ask the expert:
Have a question about enterprise threats? Send it via email today. (All questions are anonymous.)
Dig Deeper on Mobile security threats and prevention
Related Q&A from Nick Lewis
A new remote access Trojan called UBoatRAT was found spreading via Google services and GitHub. Learn how spotting command-and-control systems can ... Continue Reading
CyberArk researchers created an attack called Golden SAML that uses Mimikatz techniques and applied it to a federated environment. Learn more about ... Continue Reading
The use of botnets to spread Scarab ransomware intensifies the threat for enterprises. Discover the best way to respond to such a threat and protect ... Continue Reading
Have a question for an expert?
Please add a title for your question
Get answers from a TechTarget expert on whatever's puzzling you.