Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Endpoint

7/16/2009
06:01 PM
Connect Directly
Google+
Twitter
RSS
E-Mail
50%
50%

'Sexy View/Sexy Space' Symbian Worm Spreading

Worm's application payload comes Symbian-signed; researchers disagree over whether it's building a full-blown mobile phone botnet

A more sophisticated variant of a wily worm is using a Symbian-certified application to infect its victims via text messages, while also demonstrating botnet-like behavior, prompting some researchers to warn that it's a smartphone botnet in the making.

The so-called Sexy View/Sexy Space malware has researchers split over whether to officially call it a botnet. While Trend Micro says it's indeed a smartphone botnet, F-Secure is less convinced. "It's almost a stretch to call it a botnet, or at least a botnet in the sense that we normally think of them," says Patrik Runald, chief security advisor for F-Secure, which reported the first version of the worm to Symbian in February.

While the worm is able to update the SMS template it uses while spreading, it doesn't have other bot features, he says. "When we think of botnets, we think of a malicious program that calls home for further instructions," such as updating malware, attacking a Website, sending email, or installing an application, he says. "Sexy View does one of those features, which is the ability to update the SMS template it uses when spreading...But Sexy View doesn't have any of the other features we normally take for granted in a bot. So although it can be called a botnet, it's a very simple one with very limited, for now at least, functionality."

Jamz Yaneza, threat research manager for Trend Micro, says Sexy View/Sexy Space was actually a bot in its first iteration in February, but it was unable to successfully spread because its host site was taken down. "This mobile worm starts to steal your information, and it monitors the Websites you go to, and when you connect to the network for an update, it will do something else. That's why it has the makings of a bot," Yaneza says.

Trend Micro is investigating the host it's communicating with, he says, which appears to be out of China. Yaneza says the worm has hit more victims, although Trend Micro has no official numbers.

Botnet or not, the attack sends malware posing as a legitimate Symbian phone app with a Trojan Micro. It steals the victim's subscriber, phone, and network information, and transmits that data to a Website. It also spams SMS messages to contacts on the user's phone to continue its spread, according to Trend Micro.

The worm sends an SMS message with a URL, which, when clicked, prompts the user to install the software -- if you click "yes," then you're infected.

"It's the first malware we've seen for Symbian that is signed. This means that there's less warnings for the user when installing it. They only have to select 'yes' once, and after that, they're infected," F-Secure's Runald says. "Other malware we've seen requires the user to select 'yes' three or four times to be infected."

Runald says F-Secure believes the attackers abused a feature where Symbian allows developers to automatically sign software with specific limitations. "We believe this is how they were able to get it signed," he says.

Experts say users can protect themselves from this attack by not visiting links they receive in SMS messages, and by installing antivirus software on their smartphones.

Have a comment on this story? Please click "Discuss" below. If you'd like to contact Dark Reading's editors directly, send us a message. Kelly Jackson Higgins is the Executive Editor of Dark Reading. She is an award-winning veteran technology and business journalist with more than two decades of experience in reporting and editing for various publications, including Network Computing, Secure Enterprise ... View Full Bio

 

Recommended Reading:

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
COVID-19: Latest Security News & Commentary
Dark Reading Staff 8/10/2020
Researcher Finds New Office Macro Attacks for MacOS
Curtis Franklin Jr., Senior Editor at Dark Reading,  8/7/2020
Healthcare Industry Sees Respite From Attacks in First Half of 2020
Robert Lemos, Contributing Writer,  8/13/2020
Register for Dark Reading Newsletters
White Papers
Video
Cartoon Contest
Write a Caption, Win an Amazon Gift Card! Click Here
Latest Comment: It's a technique known as breaking out of the sandbox kids.
Current Issue
Special Report: Computing's New Normal, a Dark Reading Perspective
This special report examines how IT security organizations have adapted to the "new normal" of computing and what the long-term effects will be. Read it and get a unique set of perspectives on issues ranging from new threats & vulnerabilities as a result of remote working to how enterprise security strategy will be affected long term.
Flash Poll
The Changing Face of Threat Intelligence
The Changing Face of Threat Intelligence
This special report takes a look at how enterprises are using threat intelligence, as well as emerging best practices for integrating threat intel into security operations and incident response. Download it today!
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2019-20383
PUBLISHED: 2020-08-13
ABBYY network license server in ABBYY FineReader 15 before Release 4 (aka 15.0.112.2130) allows escalation of privileges by local users via manipulations involving files and using symbolic links.
CVE-2020-24348
PUBLISHED: 2020-08-13
njs through 0.4.3, used in NGINX, has an out-of-bounds read in njs_json_stringify_iterator in njs_json.c.
CVE-2020-24349
PUBLISHED: 2020-08-13
njs through 0.4.3, used in NGINX, allows control-flow hijack in njs_value_property in njs_value.c. NOTE: the vendor considers the issue to be "fluff" in the NGINX use case because there is no remote attack surface.
CVE-2020-7360
PUBLISHED: 2020-08-13
An Uncontrolled Search Path Element (CWE-427) vulnerability in SmartControl version 4.3.15 and versions released before April 15, 2020 may allow an authenticated user to escalate privileges by placing a specially crafted DLL file in the search path. This issue was fixed in version 1.0.7, which was r...
CVE-2020-24342
PUBLISHED: 2020-08-13
Lua through 5.4.0 allows a stack redzone cross in luaO_pushvfstring because a protection mechanism wrongly calls luaD_callnoyield twice in a row.