Welcome | Sign In
TechNewsWorld.com
Malware

First-of-Kind Viruses Target Mobile Users

Print Version
E-Mail Article
Reprints
First-of-Kind Viruses Target Mobile Users

"This latest virus represents a natural progression for virus writers, who are constantly seeking to extend their reach by spreading infections via as many platforms as possible," said David Emm, a senior technology consultant at Kaspersky Lab. "One thing's for sure -- RedBrowser may be the first of its kind, but it certainly won't be the last."


eMarketer Whitepaper: Optimizing the E-Commerce Experience
From the Web to the Contact Center, are you prepared to proactively engage and keep your savvy customers? Read how e-commerce leaders are optimizing their sites with ratings, reviews, live help, Web analytics, mobile and more.

Two new Trojan horses are being billed as "first-of-their-kind" bugs.

Security alerts are warning of a "crossover" virus that leaps from one device to another; in addition, a new Java Trojan has been detected that could infect almost any cell phone.

Crossing Over

The Mobile Malware Researchers Association (MMRA), a non-profit organization of professional researchers, on Monday announced that it has discovered the first virus that can be transferred from a PC to a mobile device -- and delete files.

The researchers received an anonymous alert about the malware, which it has dubbed "crossover" for its ability to cross-infect a Windows Mobile Pocket PC handheld from a desktop computer running the Windows operating system.

Crossover is the first malware that is able to infect both a Windows desktop computer as well as a PDA running Windows Mobile for Pocket PC, according to the MMRA.

Proving Vulnerabilities

Crossover makes a copy of itself and puts a startup command to the copy in the registry. Next, it waits for an ActiveSync connection, which synchronizes the data between a PC and a mobile device.

The virus repeatedly copies itself into the registry each time a PC is rebooted. Analysts said this could slow down the PC's performance or freeze up the computer. On the flip side, the virus copies itself to a pocket PC running the Windows CE or the Windows Mobile operating system and erases the files in the My Documents directory.

The good news is this is only a proof-of-concept virus. That means it sets out to demonstrate how easily malware could spread from one device to another. Users have no reason to panic, some analysts are saying.

"If someone starts capitalizing on the crossover worm, and we start to see increased activity, then we can talk about a global threat," Ken Dunham, senior engineer at threat intelligence firm iDefense, a VeriSign (Nasdaq: VRSN) company based in Reston, Va., told TechNewsWorld. "It's a little premature at this time."

More Mobile Phone Trojans

Meanwhile, several antivirus companies are reporting yet another Trojan this week, called RedBrowser.a. Security researchers said it is the first malicious program to infect not only smartphones, but any mobile phone capable of running Java applications.

The Trojan spreads in the guise of a program called RedBrowser, which allegedly enables the user to visit WAP sites without using a WAP connection.

According to the Trojan's author, this is made possible by sending and receiving free SMS messages. In reality, the Trojan sends SMSes to premium rate numbers. The user is charged US$5 to $6 per SMS.

"This is a social engineering worm written in Russian," Dunham said. "It is interesting when you look at it. This is a Java-based type of threat and it has been proven to be successful. We need to look at this and see what is going to be the threat down the road."

Seeing Red

The Trojan is a Java application, a JAR format archive. The file may be called "redbrowser.jar," and is 54482 bytes in size. The Trojan can be downloaded to the victim's handset either via the Internet (from a WAP site) or via Bluetooth or a personal computer.

"This latest virus represents a natural progression for virus writers, who are constantly seeking to extend their reach by spreading infections via as many platforms as possible," said David Emm, a senior technology consultant at Kaspersky Lab. "One thing's for sure -- RedBrowser may be the first of its kind, but it certainly won't be the last."

Once again, there is good news: the Trojan can be easily removed from the victim's handset using standard utilities already installed on the telephone. Still, Kaspersky Lab recommends that mobile phone users exercise caution and do not download or launch unknown programs via the Internet.


Print Version E-Mail Article Reprints More by Jennifer LeClaire


More by Jennifer LeClaire

The Digital Car: Cool Automotive Accessories, Part 2
January 16, 2007
Not all the latest high-tech automotive electronics are built to entertain. Many give the driver more information and more control. Vehicle tracking devices can tell where the car is at any time, software installed in a smartphone can turn off a vehicle's security system whenever the owner approaches, and diagnostic tools can tell what's wrong with the engine -- and how much it'll be to fix it.
'World of Warcraft' Wows 8 Million Subscribers
January 12, 2007
"World of Warcraft," the massively multiplayer online role-playing game, has reached the 8 million subscriber mark. Since debuting in North America in Nov. 2004, "World of Warcraft" has become the most popular MMORPG in the world. The franchise is available in seven different languages and is played on at least four continents.
AT&T Bids Goodbye to Cingular Brand
January 12, 2007
Starting Monday, AT&T will launch a multimedia campaign to transition the Cingular Wireless brand name into its advertising and customer communications. The campaign will integrate popular imagery, phrases and icons from Cingular's traditional advertising, including the "raising the bar" tagline, the "Jack" character and the color orange.
Don't miss a story -- sign up for our FREE e-mail newsletters and view the latest headlines at a glance.
Tech News Flash [ View Sample ]
E-Commerce Minute [ View Sample ]
ECT News Network Weekly Newsletter [ View Sample ]
Shortcuts
ECT News Network Information
Reader Services
Corporate
ECT News Network