Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Vulnerabilities / Threats

6/26/2013
11:45 PM
50%
50%

Researcher To Demo Spy-Phone At Black Hat

Using the ability to inject malicious code into applications on Android devices, a researcher will demonstrate at Black Hat how to create the infrastructure to spy on mobile users

Security researchers have warned that mobile phones could easily be made into surveillance devices that can track users, record audio and video of their surroundings, and eavesdrop on their communications. Now one researcher plans to show off a proof-of-concept program at the Black Hat Security Briefings this summer that can compromise a phone and turn it into just such an eavesdropping platform.

Click here for more of Dark Reading's Black Hat articles.

The program, created by researchers at network security firm Kindsight, essentially turns any Android phone into a compromised bot, allowing the attacker to eavesdrop on communications, track location, download personal information and take pictures without the victim's knowledge. In addition, the researchers will show how they developed the architecture of the eavesdropping software and ways that it can be easily added as a Trojan Horse to any mobile app.

"This is a demonstration, a proof-of-concept malware," says Kevin McNamee, security architect and director of Kindsight's Security Labs. "We use this as a way to show the capabilities of the malware and show how dangerous cyberespionage can be."

While only a small fraction of U.S. mobile users are impacted by malware, spyware makes up a large portion of the pantheon of mobile threats. As of March 2013, almost two out of every 10 malicious mobile applications qualifies as spyware, according to Juniper Networks' Mobile Threat Center. The company classifies any program that captures and transfer sensitive data on the phone without notifying the user as spyware.

[A spate of research into mobile devices as sensor platforms has shown that compromised smartphones can be turned into insiders -- eavesdropping on phone calls, 'shoulder-surfing' for passwords, or looking around an office. See Mobile Trojans Can Give Attackers An Inside Look.]

In its Third Annual Mobile Threats Report, Juniper described a current threat that could easily be used for espionage by its operators. Known as NotCompatible, the malware turns an Android phone into a compromised node on a botnet, allowing an attacker to gain insider access to a corporate network.

"It is important to note the complexity of these threats varies significantly depending on the sophistication of the attacker," says Michael Callahan, vice president of global security-product marketing at Juniper Networks. "The most complex attacks are capable of leveraging the device to probe into the broader corporate network, while others simply monitor activities on the device."

In the Kindsight demonstration, the researchers will not show off any novel ways of compromising a device, instead relying on a standard phishing attack to convince the victim to install a fake application. However, by creating a trojanized application, the attacker could easily fool the target, if they can convince the victim to install an application from a place other than the Google Play store.

"We can take an application from Google Play, open it up, take it apart, and put this spy-phone service into that application," Kindsight's McNamee says.

The current incarnation of DroidWhisper uses Web-based command-and-control communications to send data and receive instructions from a server on the Internet. However, it could be programmed to exchange information via short message service (SMS) text messaging.

The company stopped short of adding aggressive reconnaissance functionality, McNamee says. By installing network utilities, a phone could be used as a portable network scanner, finding vulnerabilities in corporate networks and infecting additional systems.

"There are some things that we have not taken to the logical extreme," McNamee says. "That is a little bit too over the top."

Companies worried about attackers using employees' mobile devices as eavesdropping platforms should focus on two defensive measures. Inspecting network traffic for signs of malicious traffic can help pinpoint malware that sneaks into a network. And host-based defenses could detect when malware attempts to spread.

"When these personal devices connect to the corporate network, it’s vital that companies also implement secure access controls that can limit the privileges of these devices," says Juniper's Callahan. "These solutions also provide a way to control the types of devices connecting to the network by identifying device type, checking the device’s security posture and then enforcing secure access controls and policies."

Have a comment on this story? Please click "Add Your Comment" below. If you'd like to contact Dark Reading's editors directly, send us a message. Veteran technology journalist of more than 20 years. Former research engineer. Written for more than two dozen publications, including CNET News.com, Dark Reading, MIT's Technology Review, Popular Science, and Wired News. Five awards for journalism, including Best Deadline ... View Full Bio

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
JasonK311
50%
50%
JasonK311,
User Rank: Apprentice
4/28/2015 | 4:45:44 AM
NSA did their duty
NSA did their duty. I think if you have an android device you can easily spy on others by ikeyMonitor Mobile Phone Spy App. It works invisibly. Anyway, thanks for sharing the post. 
DNS Firewalls Could Prevent Billions in Losses to Cybercrime
Curtis Franklin Jr., Senior Editor at Dark Reading,  6/13/2019
7 Truths About BEC Scams
Ericka Chickowski, Contributing Writer,  6/13/2019
Register for Dark Reading Newsletters
White Papers
Video
Cartoon
Current Issue
Building and Managing an IT Security Operations Program
As cyber threats grow, many organizations are building security operations centers (SOCs) to improve their defenses. In this Tech Digest you will learn tips on how to get the most out of a SOC in your organization - and what to do if you can't afford to build one.
Flash Poll
The State of IT Operations and Cybersecurity Operations
The State of IT Operations and Cybersecurity Operations
Your enterprise's cyber risk may depend upon the relationship between the IT team and the security team. Heres some insight on what's working and what isn't in the data center.
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2019-12868
PUBLISHED: 2019-06-18
app/Model/Server.php in MISP 2.4.109 allows remote command execution by a super administrator because the PHP file_exists function is used with user-controlled entries, and phar:// URLs trigger deserialization.
CVE-2019-12865
PUBLISHED: 2019-06-17
In radare2 through 3.5.1, cmd_mount in libr/core/cmd_mount.c has a double free for the ms command.
CVE-2017-10720
PUBLISHED: 2019-06-17
Recently it was discovered as a part of the research on IoT devices in the most recent firmware for Shekar Endoscope that the desktop application used to connect to the device suffers from a stack overflow if more than 26 characters are passed to it as the Wi-Fi name. This application is installed o...
CVE-2017-10721
PUBLISHED: 2019-06-17
Recently it was discovered as a part of the research on IoT devices in the most recent firmware for Shekar Endoscope that the device has Telnet functionality enabled by default. This device acts as an Endoscope camera that allows its users to use it in various industrial systems and settings, car ga...
CVE-2017-10722
PUBLISHED: 2019-06-17
Recently it was discovered as a part of the research on IoT devices in the most recent firmware for Shekar Endoscope that the desktop application used to connect to the device suffers from a stack overflow if more than 26 characters are passed to it as the Wi-Fi password. This application is install...