SophosLabs have come across yet more samples of Android malware exploiting the so-called Master Key vulnerability. The vulnerability is not being widely used yet, but there does seem to be more than just a passing interest from the cybercrooks in exploiting it. As we discussed last month, the exploit doesnt actually crack any cryptographic keys, despite its name. The way it works is annoyingly simple. Android apps are delivered in ZIP-format files with the extension APK (Android Package)”]

