Top Tech News

CIO Today Network Sites:   Top Tech News  |   CIO Today   |   Mobile Tech Today   |   Data Storage Today
News & Product Reviews for Tech Leaders
Tuesday, February 9th 
Home
Network Security
Microsoft/Windows
Linux/Open Source
Apple/Macintosh
Wireless Tech
World Wide Web
Tech Trends
Data Storage
Software
Hardware
Communications
Spam & Hackers
Chips & Processors
E-Business
Personal Tech
 

Advertisement
Data Security

Malware Attacks Target Mobile Devices

Malware Attacks Target Mobile Devices
March 4, 2008 2:15PM

Bookmark and Share
A recent mobile-device attack was a Trojan bundled in legitimate files. The mobile-device malware sent out information about the device and shut off other forms of security on the mobile device. McAfee researchers have also seen an attack aimed at Symbian phones. A mobile-phone attack in China shut down the phone until a payment was made.


Malicious-code attacks are being aimed at mobile devices, security researchers say. The malware, which comes hidden inside legitimate applications, can compromise information on the device and even target the user for extortion.

One recent attack was a Trojan called WinCE/InfoJack that was aimed at Windows Relevant Products/Services Mobile PocketPCs. Dave Marcus, security research and communications Relevant Products/Services manager of McAfee Avert Labs, told us that WinCE/InfoJack was bundled with legitimate installation files such as Google Maps, games and stock-trading applications, and then distributed across a variety of Web sites. "That's a technique we've seen utilized in the PC malware for quite some time," Marcus said, but is still new in attacks on mobile platforms.

The Trojan sends out information about the device (such as its serial number and operating system Relevant Products/Services) to the owner of a now-offline Web site in China. It's a particularly dangerous attack because it shuts off other forms of security. Devices require authorization to allow programs to be installed, Marcus said. "This malware shut down that functionality, which could then allow the malware to update itself or allow other people to put malware on the phone."

Modular Malware

Another malware attack noted by McAfee researchers is aimed at Symbian Series 60 phones, available from manufacturers including Nokia, Panasonic, and Samsung. Also based in China, the SymbOS/Kiazha attack was designed to extort money from an infected user by disabling the phone until a payment of roughly $7 is made via QQ, a popular instant-messaging network Relevant Products/Services in China that features "coins" that function as an in-network currency.

The SymbOS/Kiazha malware is included in a "toolkit" of malicious software known as MultDropper. Modular suites of attack tools are common for malicious code aimed against PCs, and Marcus said that it's the trend in mobile attacks now as well. "It doesn't surprise us as security researchers that the success of PC malware is replicated on the mobile platform. There are different considerations on mobile platform, but I think you're going to see people model their attacks on the mobile platform after the success of the PC platform," he said.

Professionally Written

The MultDropper that included the Symbian attack tool was written by someone who tested it extensively before unleashing it. Marcus noted that some of its components seemed at first to run in opposition. For example, infected phones would send a text message to open a new QQ account into which the extortion money could be paid, while another function would delete sent and received text messages.

Marcus said that whoever created the attack made sure the different components were working in harmony to make the extortion happen without leaving a trail. "When you looked at how the stages worked in conjunction with each other, he was using it to cover his tracks," Marcus said.

These attacks are indicative of a trend of attacks distributed to local niche markets, Marcus said. "While this attack was targeted only to Chinese speakers, it speaks to the fact that if you're a world traveler, you have to educate yourself about the local threats and nuances to technology, because with these kinds of trends developing, you're going to be exposed to things in china that you wouldn't be exposed to in Japan, Brazil or the United States," he told us.

Advertisement



 Data Security
1. China Busted Hacker-Training Site
2. FBI Tackles Haiti-Relief Scams
3. Patch Tuesday Will Tie MS Record
4. Google Apps Controls Mobile Devices
5. Torrent Traps Used To Harvest Logins


advertisement

Have an informed opinion on this story?
Send a Letter to the Editor.
We want to know what you think.
Send us your Feedback.

 Related Topics  Latest News & Special Reports

  Analysts Expect iPad Price To Drop
  The Dearth of Female Entrepreneurs
  China Busted Hacker-Training Site
  Nook E-Reader Heads to Retail Stores
  Veteran SAP CEO Abruptly Resigns

 Technology Marketplace
Compliance
Stand out from other IS Professionals and increase your earning potential.®).
 
Enterprise Hardware
Now is the best time to buy a new APC Smart-UPS!
HP ProLiant G6 Servers: Perform like a superstar, Save like an accountant www.hp.com
 
Enterprise I.T.
Learn how Microsoft server upgrades can create efficiencies
Stand out from other IS Professionals and increase your earning potential.®).
 
Hardware
Find out why now is the best time to buy a new APC Smart-UPS!
 
Microsoft/Windows
Read about how to add efficiencies with Microsoft Virtualization.
 
Network Security
AT&T Synaptic Compute as a Service. Boost your power on demand.
 
Mobile Enterprise Spotlight

Analysts See iPad Price Drop, with Some Cannibalization
Just weeks before Apple officially rolls out the iPad, financial analysts are making pricing predictions. But could the analysis itself hinder the initial demand for the pricey tablet computer?

Bar Codes Go Mobile, Get Hip Again
For decades, retailers have used patterns of black dots and lines to encode data onto products. Now, bar codes are gaining favor as an easy way for cell-phone users to view ads and other data instantly.

'Dead Simple, Dirt Cheap' JooJoo Tablet Shipping Soon
The JooJoo, a web-browsing tablet device that is the subject of a high-profile legal dispute, appears on track to reach buyers at the end of February, but the tablet scene has dramatically changed.

Advertisement
Enterprise Software Spotlight

Google May Add Facebook, Twitter Links to Gmail
Google will reportedly roll more social-networking features into Gmail, the fastest-growing e-mail service. The new features could save users the trouble of switching to Facebook or Twitter.

SAP CEO Abruptly Resigns; Co-CEOs Will Take Over
Business-software maker SAP announced an abrupt strategic shift in the corporate suite with Léo Apotheker resigning as CEO, to be replaced by co-CEOs Bill McDermott (left) and Jim Hagemann Snabe (right).

Cybersecurity Vendors Look Hot in 2010
Tech-security companies are poised to become Wall Street darlings this year, thanks in part to Google's tiff with China, which reinforced an already positive outlook for major security vendors.

Advertisement
Navigation
Top Tech News
Home/Top News | Network Security | Microsoft/Windows | Linux/Open Source | Apple/Macintosh | Wireless Tech | World Wide Web
Tech Trends | Data Storage | Software | Hardware | Communications | Spam & Hackers | Chips & Processors
E-Business | Personal Tech
Also visit these Enterprise Technology Sites
Top Tech News | CIO Today | Mobile Tech Today | Data Storage Today

Services:
FreeNewsFeed | Free Newsletters | Free Whitepapers | XML/RSS Feed

About CIO Today Network | How To Contact Us | Article Reprints | Services for PR Pros (In partnership with NewsFactor) | Top Tech Wire | How To Advertise

Privacy Policy | Terms of Service
© Copyright 2000-2010 Top Tech News. All rights reserved. Article rating technology by Blogowogo.