Risk
1/24/2011
10:08 PM
George V. Hulme
George V. Hulme
Commentary
Connect Directly
RSS
E-Mail
50%
50%

New Age of Mobile Malware On Way

New types of malware are emerging, designed specifically to exploit the unique features of mobile handsets.

New types of malware are emerging, designed specifically to exploit the unique features of mobile handsets.People carry their mobile handsets everywhere. And they're increasingly using their smartphones as the portals into their lives: GPS navigation, social networking, camera, and staying in touch via e-mail and, sometimes, even phone calls.

Such as the Geinimi Trojan, we covered in December, that was targeting Android phones. Or the virus that infected 1 million cell phones in China, and would automatically send text messages. There have been many others, including proof-of-concept viruses and bogus applications aimed at app stores.

Recently researchers at the City University of Hong Kong and Indiana University decided to see what malware they could develop that would take advantage of some of the capabilities specific to mobile handsets.

What came from their research they're calling Soundminer, an emerging kind of sensory-based malware:

In this paper, we report our research on sensory malware, a new strain of smartphone malware that uses on-board sen- sors to collect private user information. We present Sound- miner, a stealthy Trojan with innocuous permissions that can sense the context of its audible surroundings to target and extract a very small amount of high-value data.

As sensor-rich smartphones become more ubiquitous, sensory malware has the potential to breach the privacy of individuals at mass scales. While naive approaches may up- load raw sensor data to the malware master, we show that sensory malware can be stealthy and put minimal load on the malware master's resources.

Soundminer snoops on phone calls and can reportedly record when a user keys in, or speaks, a credit card number into their phone. And it can, its creators claim, successfully avoid anti-virus detection.

The student's research paper is available here [.pdf].

Get ready for a new kind of malware. Malware that takes advantage of the phone, text messages, camera, GPS, downloaded applications, and mobile transactions.

The malware that is produced will only be limited by malware authors' imaginations and the ability of mobile operating systems and security software to detect and stop it.

It's going to be a fascinating few years.

For my security and technology observations, find me on Twitter.

Comment  | 
Print  | 
More Insights
Register for Dark Reading Newsletters
White Papers
Cartoon
Current Issue
Flash Poll
Video
Slideshows
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2014-3352
Published: 2014-08-30
Cisco Intelligent Automation for Cloud (aka Cisco Cloud Portal) 2008.3_SP9 and earlier does not properly consider whether a session is a problematic NULL session, which allows remote attackers to obtain sensitive information via crafted packets, related to an "iFrame vulnerability," aka Bug ID CSCuh...

CVE-2014-3908
Published: 2014-08-30
The Amazon.com Kindle application before 4.5.0 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

CVE-2010-5110
Published: 2014-08-29
DCTStream.cc in Poppler before 0.13.3 allows remote attackers to cause a denial of service (crash) via a crafted PDF file.

CVE-2012-1503
Published: 2014-08-29
Cross-site scripting (XSS) vulnerability in Six Apart (formerly Six Apart KK) Movable Type (MT) Pro 5.13 allows remote attackers to inject arbitrary web script or HTML via the comment section.

CVE-2013-5467
Published: 2014-08-29
Monitoring Agent for UNIX Logs 6.2.0 through FP03, 6.2.1 through FP04, 6.2.2 through FP09, and 6.2.3 through FP04 and Monitoring Server (ms) and Shared Libraries (ax) 6.2.0 through FP03, 6.2.1 through FP04, 6.2.2 through FP08, 6.2.3 through FP01, and 6.3.0 through FP01 in IBM Tivoli Monitoring (ITM)...

Best of the Web
Dark Reading Radio
Archived Dark Reading Radio
This episode of Dark Reading Radio looks at infosec security from the big enterprise POV with interviews featuring Ron Plesco, Cyber Investigations, Intelligence & Analytics at KPMG; and Chris Inglis & Chris Bell of Securonix.