Perimeter
9/26/2011
11:07 PM
Gadi Evron
Gadi Evron
Commentary
50%
50%

Eavesdropping Trojans Used In Cell Phone Spying Case

Israeli case a reminder of all types of social engineering threats

A story broke out recently in Israel about the arrest of 22 private investigators over the wide-use of eavesdropping Trojan horses for cell phones. This one also has an interesting solution for discovering the attack.

Reportedly, the Trojan horse, called "SpyPhone," costs (depending on target phone) between $1,500 and $2,500. Its capabilities vary from recording conversations and opening the microphone to listening to the room the phone is in.

The technology is available for multiple phones, from an ancient Nokia 5500 to a modern iPhone. While it is obvious the capabilities of the Trojan horse change with how advanced the phone is, the attack vectors seem to be human -- social engineering.

It has been reported that automatic attacks have been used previously by use of software vulnerabilities, and some are still rumored. However, that does not seem to be the case here. The infection vectors varied from asking someone for his phone for a few seconds, sending an SMS and receiving a download link, to downloading it directly. Other approaches, such as SMS and MMS lures to get the target user to click on a link, are also suspected.

Local police intend to take this investigation forward to also investigate the clients of the PI's, and it is rumored that many of those are wives wishing to spy on their husbands.

This is not the first time such a case was prosecuted in Israel. In 2005, private investigators in Israel used a Trojan horse to perform industrial espionage. Dozens of international, high-tech companies were implicated, either as clients of private intelligence companies that did the spying or as the victims.

The case from 2005 was the first real (and public) example of industrial espionage by the use of Trojan horses with computers. While it is clear that espionage by the use of cell phones and with Trojan horses isn't new, this Israeli case once again brings to light that these risks are in actuality threats -- real and demonstrated.

White such targeted attacks, especially when used in combination with 0-day vulnerabilities (or as some people like to call them these days, APTs) are difficult to discover, unlike on the PC, cell phones do not provide us with as many options other than returning the machine to company settings (hoping that it was a software matter).

That is not a scalable solution, and it is my hope that new solutions will be designed into future phones, rather than someone making a buck off of mostly useless (for such attacks) antiviruses for cell phones.

There is, however, a solution for finding out if you are a victim in this specific case, as suggested on a Hebrew news site ynet: As this Trojan horse is reported to send an SMS to its masters if the SIM card on the phone is changed. Change it. Buy a disposable SIM for $10. Then check your balance to see if it was reduced by a few cents. If it was, you're being spied upon.

This is a brilliant and simple solution -- but, naturally, only if this is how the Trojan horse actually works, and until such time as the makers of the program update it to counter this. The program is sold legally, even though the website looks shady. It is the malicious use by the PIs that's illegal.

Gadi Evron is an independent security strategist based in Israel. Special to Dark Reading.

Comment  | 
Print  | 
More Insights
Register for Dark Reading Newsletters
White Papers
Cartoon
Current Issue
Flash Poll
Title Partner’s Role in Perimeter Security
Title Partner’s Role in Perimeter Security
Considering how prevalent third-party attacks are, we need to ask hard questions about how partners and suppliers are safeguarding systems and data.
Video
Slideshows
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2013-7421
Published: 2015-03-02
The Crypto API in the Linux kernel before 3.18.5 allows local users to load arbitrary kernel modules via a bind system call for an AF_ALG socket with a module name in the salg_name field, a different vulnerability than CVE-2014-9644.

CVE-2014-8160
Published: 2015-03-02
net/netfilter/nf_conntrack_proto_generic.c in the Linux kernel before 3.18 generates incorrect conntrack entries during handling of certain iptables rule sets for the SCTP, DCCP, GRE, and UDP-Lite protocols, which allows remote attackers to bypass intended access restrictions via packets with disall...

CVE-2014-9644
Published: 2015-03-02
The Crypto API in the Linux kernel before 3.18.5 allows local users to load arbitrary kernel modules via a bind system call for an AF_ALG socket with a parenthesized module template expression in the salg_name field, as demonstrated by the vfat(aes) expression, a different vulnerability than CVE-201...

CVE-2015-0239
Published: 2015-03-02
The em_sysenter function in arch/x86/kvm/emulate.c in the Linux kernel before 3.18.5, when the guest OS lacks SYSENTER MSR initialization, allows guest OS users to gain guest OS privileges or cause a denial of service (guest OS crash) by triggering use of a 16-bit code segment for emulation of a SYS...

CVE-2014-8921
Published: 2015-03-01
The IBM Notes Traveler Companion application 1.0 and 1.1 before 201411010515 for Window Phone, as distributed in IBM Notes Traveler 9.0.1, does not properly restrict the number of executions of the automatic configuration option, which makes it easier for remote attackers to capture credentials by c...

Dark Reading Radio
Archived Dark Reading Radio
How can security professionals better engage with their peers, both in person and online? In this Dark Reading Radio show, we will talk to leaders at some of the security industry’s professional organizations about how security pros can get more involved – with their colleagues in the same industry, with their peers in other industries, and with the IT security community as a whole.