Smartphone malware: Still the next big thing?

By Tim Conneally | Published April 16, 2009, 1:43 PM

Microworms (courtesy BuyMicroWorms.com)Conficker may have dominated security headlines this quarter, but Finnish security company F-Secure says the lesser-known "Sexy View" worm represented a new threat: the SMS and phone-based worm and the mobile botnet.

Sexy View is a social engineering worm which uses a device's contact list to spread. It sends a text message to all contacts with a link to a Web site that installs a malicious application that shares the phone's information (like its serial number) with the virus' creators. It targets devices running Symbian S60 3rd edition and was first found on Nokia 3250 handsets.

"It is the first text message worm ever." said F-Secure's Chief Research Officer Mikko Hypponen. "It's also the first mobile phone worm that circumvents the signature checks that are meant to secure the latest smartphones. And the motive behind it seems to be to collect information for mobile phone spamming purposes. Mobile phone spam is already a big problem in some parts of the world -- eventually it will be an issue everywhere."

But there have already been hundreds of malwares for Symbian besides simple text messaging, and the opportunities for them to be fruitful and multiply extend further than mere spam. Last week, Visa introduced the world's first Near Field Communications technology for "wallet phones," where an NFC chip with the owner's bank information is installed in the phone, allowing simple SpeedPass style use in transactions.

Fortunately, the first handset to use the technology is the Nokia 6212, which runs Nokia S40, a non-Symbian operating system that does not let the user install new applications.

F-Secure is understandably concerned with mobile threats of this nature, as it's been the default anti-virus software provider for a number of Nokia devices since 2004. Hypponen has repeatedly warned the public that the increasing connectivity of mobile devices provides new ingress for malware.

Shortly after signing a deal with F-Secure, Nokia enlisted the help of Symantec for the protection of S60 and UIQ devices, and Trend Micro offers a number of mobile virus protection services, which includes not only protection for Symbian devices, but also for Windows Mobile for both PocketPC and Smartphone.

There's a catch to this, though, and perhaps you've already spotted it.

Most of the alarmist reports of mobile infections in the last few years have come from companies that also happen to make mobile virus protection software, spawning the question: "Are Symbian and Windows Mobile mobile devices actually in danger, or is this simply a case of manufactured demand -- nay, fearmongering -- by security providers?"

Fortunately, there is now more nonpartisan conviction to back up the fear. A recently published study funded by Deutsche Telekom examined anomaly detection in smartphones, and came to this conclusion: "We believe that the evolution of malware for mobile devices will take a similar direction as the evolution of PC malware. Thus, similar problems will have to be encountered, e.g., missing signatures for unknown threats and new malwares appearing at high frequency."

The group tested several different malware classes on a Nokia E61 running Symbian OS 9.1, a Nokia 7610 running S60 7.x, and an HTX TyTN B running Windows Mobile 5. One virus the group tested took a picture through the Nokia E61's front camera when the keypad was being used, guaranteeing a shot of the user. This picture was then sent via MMS to a pre-defined mobile number. Another malware was remotely controlled by SMS messages which could delete the user's entire phonebook when the SMS was opened.

However, these malwares are not likely to be encountered in the wild, as they were created by the research group. The group said that, despite their best efforts, they had to make their own to produce realistic results because there is actually a sufficient lack of available smartphone malware for newer platforms.

Nonetheless, the group finds that protection is absolutely needed, but as is the case with PC anti-virus software, signature-based protection methods are simply not good enough.

[Picture of real micro-worms courtesy of BuyMicroWorms.com]

Comments

View comments by with a score of at least

Good. I hate smart phones. Blackjack ...... gone. iPhone......gone after two months, and finally I went back to the only phone that can actually send and receive calls from my basement, the cheap a** and free Motorola RAZR.

My idiot, unemployed, and broke friend just met a new woman about two weeks ago. They both ran out and got iPhones and matching Bluetooth headsets. It just goes to show what I've always said, if you don't have money, act like you do. They both are always dressed up, wearing cologne, and are broke as ****.

All they do is shop and eat out, running up thousands of dollars on credit cards with one unemployment check coming in. His Honda is about to be repossessed, she has no car, but they had to have those iPhones.

Bring on the viruses and malware.

Retards.

Score: 0

|

This had to happen sometime, but it will certainly suck when it does. With much larger market shares, I'm afraid that Apple and Linux OS's won't be immune this time.

Great article.

Score: 0

|

Microsoft's Ray Ozzie: 'Nobody's going to be 100% open'

The mobile apps ecosystems of the world may converge over time, led by apps being ported over across platforms, according to the Chief Software Architect.

Will Firefox beat IE9 to Direct2D rendering?

Just days after Microsoft executives gave conference attendees a peek at a new rendering technology, a Mozilla contributor revealed he's working on the same thing.

Where there's smoke: Apple warranty stance raises troubling questions

Carmi Levy | Wide Angle Zoom: Smoking can be dangerous not only for your lungs, it appears, but for your Apple hardware warranty.

The fallacy of Facebook privacy

Carmi Levy | Wide Angle Zoom: If an insurance company learns something interesting about its client through the Internet, is that snooping?

Microsoft 'worked with Apple' for Silverlight on iPhone, says Goldfarb

By not making such a big deal out of trying to stream video to the iPhone, Microsoft got a big deal out of it, revealed the Silverlight product manager.

Clicker.com cuts through the Web video chaos

In a world where homemade video and Hollywood movies travel the same pipeline, it's good to have a real search engine to cut through the clutter.

A case study in improving software: What Office 2010 can learn from Notion 3

A music composition product gambles with a complete overhaul, in an effort to make headway against two well-known competitors in a tough market.

Kindle 2 update adds battery life, native PDF reader

Amazon has pushed out an update to the Kindle 2 e-reader that lengthens battery life and adds a native PDF viewer.

Safari on iPhone gets competition from a $1 browser app

Apple likes to say it gives iPhone users a full browsing experience, but a new competitor tries to incorporate more desktop browser features.

Action Replay maker sues Microsoft for Xbox 360 'predatory technological barriers'

Third-party video game accessory maker Datel has filed an antitrust lawsuit against Microsoft over the Xbox 360's recent Dashboard update.