First SMS Trojan for Android is in the wild

John Leyden, The Register, 8/10/2010

Premium rate scam will cost Google phoners dear

The first text message-based Trojan to infect smartphones running Google’s Android operating system has been detected in the wild.

Trojan-SMS.AndroidOS.FakePlayer-A poses as a harmless media player application and has already infected a number of mobile devices, Russian security firm Kaspersky Lab warns. Prospective marks are prompted to install a “media player file” of just over 13 KB with the standard Android .APK extension.

Once installed, the Trojan begins sending SMS messages to premium-rate numbers without the owner’s knowledge or consent. Victims wind up with a huge bill while the cybercrooks behind the scheme earn a slice of the income. There have been isolated cases of devices running Android getting infected with spyware since last year, but this is the first occasion that an SMS-spewing Trojan, common in the world of mobile malware, has affected devices running Google’s operating system.

Denis Maslennikov, mobile research group manager at Kaspersky Lab, said the success of the Android platform in the marketplace has triggered increased interest from virus writers. The Russian security firm plans to respond to the increased threat with a new mobile security product, Kaspersky Mobile Security for Android, in early 2011.

Users are advised to pay close attention to the services that an application requests access to during installation. If a user agrees to permit an application to access premium rate service during installation, the smartphone may then be able to make calls and send SMSs without further authorisation.

In related news, BBC journalists created a mobile application with hidden spy functionality as part of an exercise designed to demonstrate how straightforward it has become to create a malicious application for a smartphone. The application was put together using standard components from software toolkits that developers use to create programs for handsets, an approach that might make the malware harder to detect. The malware was not released into the wild or placed in an app store so no hacking of innocent PCs or smartphones was involved. Thus the exercise was far less ethically fraught than BBC Click’s botnet spamming jape last year.

Application security firm Veracode helped BBC hack Mark Ward build the basic game of noughts-and-crosses with hidden backdoor spying functionality. “The spyware took up about 250 lines of the 1500 making up the entire program,” Ward reports. ®

Share

Related posts:

  1. New Trojan Hits Android, Study Suggests Better Smartphone Security Mark Kurlyandchik, DailyTech, 9/13/2010 While viruses are not nearly as common on mobile devices as they are on personal computers,...
  2. Banking Trojan hits Android phones Brad Reed, Network World, 7/14/2011 Android users hit by banking Trojan that has plagued Symbian, BlackBerry and Windows Phone users...
  3. Zeus Trojan Infects BlackBerry via SMS Nan Palmero, BlackberryCool, 3/8/2011 BlackBerry is a mostly secure platform, but information on a new Zeus Trojan that has migrated...
Posted on August 10, 2010 at 10:11 am by lesliemanzara · Permalink
In: Android, Mobile Technology · Tagged with: ,

2 Responses

Subscribe to comments via RSS

  1. Written by MobileInternetS
    on August 10, 2010 at 3:11 pm
    Permalink

    First SMS Trojan for Android is in the wild http://is.gd/ebzjq

  2. Written by MobileInternetS
    on August 11, 2010 at 2:13 pm
    Permalink

    First SMS Trojan for Android is in the wild http://bt.io/FnUe

Subscribe to comments via RSS

Leave a Reply