Risk
1/24/2011
10:08 PM
George V. Hulme
George V. Hulme
Commentary
50%
50%

New Age of Mobile Malware On Way

New types of malware are emerging, designed specifically to exploit the unique features of mobile handsets.

New types of malware are emerging, designed specifically to exploit the unique features of mobile handsets.People carry their mobile handsets everywhere. And they're increasingly using their smartphones as the portals into their lives: GPS navigation, social networking, camera, and staying in touch via e-mail and, sometimes, even phone calls.

Such as the Geinimi Trojan, we covered in December, that was targeting Android phones. Or the virus that infected 1 million cell phones in China, and would automatically send text messages. There have been many others, including proof-of-concept viruses and bogus applications aimed at app stores.

Recently researchers at the City University of Hong Kong and Indiana University decided to see what malware they could develop that would take advantage of some of the capabilities specific to mobile handsets.

What came from their research they're calling Soundminer, an emerging kind of sensory-based malware:

In this paper, we report our research on sensory malware, a new strain of smartphone malware that uses on-board sen- sors to collect private user information. We present Sound- miner, a stealthy Trojan with innocuous permissions that can sense the context of its audible surroundings to target and extract a very small amount of high-value data.

As sensor-rich smartphones become more ubiquitous, sensory malware has the potential to breach the privacy of individuals at mass scales. While naive approaches may up- load raw sensor data to the malware master, we show that sensory malware can be stealthy and put minimal load on the malware master's resources.

Soundminer snoops on phone calls and can reportedly record when a user keys in, or speaks, a credit card number into their phone. And it can, its creators claim, successfully avoid anti-virus detection.

The student's research paper is available here [.pdf].

Get ready for a new kind of malware. Malware that takes advantage of the phone, text messages, camera, GPS, downloaded applications, and mobile transactions.

The malware that is produced will only be limited by malware authors' imaginations and the ability of mobile operating systems and security software to detect and stop it.

It's going to be a fascinating few years.

For my security and technology observations, find me on Twitter.

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
Register for Dark Reading Newsletters
White Papers
Video
Cartoon Contest
Current Issue
Security Operations and IT Operations: Finding the Path to Collaboration
A wide gulf has emerged between SOC and NOC teams that's keeping both of them from assuring the confidentiality, integrity, and availability of IT systems. Here's how experts think it should be bridged.
Flash Poll
New Best Practices for Secure App Development
New Best Practices for Secure App Development
The transition from DevOps to SecDevOps is combining with the move toward cloud computing to create new challenges - and new opportunities - for the information security team. Download this report, to learn about the new best practices for secure application development.
Slideshows
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2017-0290
Published: 2017-05-09
NScript in mpengine in Microsoft Malware Protection Engine with Engine Version before 1.1.13704.0, as used in Windows Defender and other products, allows remote attackers to execute arbitrary code or cause a denial of service (type confusion and application crash) via crafted JavaScript code within ...

CVE-2016-10369
Published: 2017-05-08
unixsocket.c in lxterminal through 0.3.0 insecurely uses /tmp for a socket file, allowing a local user to cause a denial of service (preventing terminal launch), or possibly have other impact (bypassing terminal access control).

CVE-2016-8202
Published: 2017-05-08
A privilege escalation vulnerability in Brocade Fibre Channel SAN products running Brocade Fabric OS (FOS) releases earlier than v7.4.1d and v8.0.1b could allow an authenticated attacker to elevate the privileges of user accounts accessing the system via command line interface. With affected version...

CVE-2016-8209
Published: 2017-05-08
Improper checks for unusual or exceptional conditions in Brocade NetIron 05.8.00 and later releases up to and including 06.1.00, when the Management Module is continuously scanned on port 22, may allow attackers to cause a denial of service (crash and reload) of the management module.

CVE-2017-0890
Published: 2017-05-08
Nextcloud Server before 11.0.3 is vulnerable to an inadequate escaping leading to a XSS vulnerability in the search module. To be exploitable a user has to write or paste malicious content into the search dialogue.

Dark Reading Radio
Archived Dark Reading Radio
In past years, security researchers have discovered ways to hack cars, medical devices, automated teller machines, and many other targets. Dark Reading Executive Editor Kelly Jackson Higgins hosts researcher Samy Kamkar and Levi Gundert, vice president of threat intelligence at Recorded Future, to discuss some of 2016's most unusual and creative hacks by white hats, and what these new vulnerabilities might mean for the coming year.