EDITION:GLOBALNORTH AMERICACENTRAL & SOUTH AMERICAUK & IRELANDEUROPEMIDDLE EAST & AFRICAAUSTRALIA & NEW ZEALANDASIA
LANGUAGES:

Welcome
to ContactCenterWorld.com

Raj Wadhwani
President

President of Contact Center World
Wednesday, May 23, 2012
Learn the best practices in the industry from those who 'do the job' every day - click on Top Performers Conferences under conferences and events
OVER 129,000 MEMBERS

The Global Association for Contact Center Best Practices & Networking


Site Map
About this Site
Contact Us


 
 Pulse Survey

Global Benchmarking Study Promo

FEATURED SUPPLIERS
on ContactCenterWorld.com this week:

Global Benchmarking Study of Top Performers







Click on the company name for more details!


View:Folder:
Read:Page:
Order:Asc/Des:
To:CC:
Reply:Forward:
SearchP1:BCC:
Stack:
Error:
First SpyEye Attack on Android Mobile Platform is Virtually Undetectable

Trusteer intelligence has spotted the first SpyEye variant, called SPITMO, attacking Android devices in the wild. According to Amit Klein, Trusteer’s chief technology officer, the threat posed by DriodOS/Spitmo has escalated the danger of SpyEye now that this malicious software has been able to shift its delivery and infection methods.

Amit clarifies, "We always said it was just a matter of time before the true potential of SpitMo was realised. When it first emerged back in April F-Secure reported, in its blog, that it was targeting European Banks. The trojan injected fields into a bank's webpage asking the customer to input his mobile phone number and the IMEI of the phone. The fraudster then needed to follow a cumbersome three stage sequence - get the IMEI number; generate a certificate; then release an updated installer. This process could take up to three days.

"We couldn’t believe fraudsters would go to that much effort just to steal a couple of SMSs - and it appears we were right. Information gathered by Trusteer's Intelligence Centre has discovered a new far more intuitive, and modern, approach of SPITMO for Android now active in the wild."

SPITMO – Moving on to Android

Looking at the attack vector in action, Amit explains, "When a user browses to the targeted bank a message is injected presenting a "new" mandatory security measure, enforced by the bank, in order to use its online banking service. The initiative pretends to be an Android application that protects the phone’s SMS messages from being intercepted and will protect the user against fraud. How’s that for irony!"

Once the user clicks on "set the application" they are given further instructions to walk them though downloading and installing the application.

To complete the installation, the user is instructed to dial the number "325000"; the call is intercepted by the Android malware and an ‘alleged’ activation code is presented, to be submitted later in to the "bank’s site". Besides concealing the true nature of the application, this "activation code" does not serve any legitimate purpose.

Once the Trojan has successfully installed, all incoming SMS messages will be intercepted and transferred to the attacker’s Command and Control server (C&C). A code snippet is run when an SMS is received, creating a string, which will later be appended as a query string to a GET HTTP request, to be sent to the attacker's drop zone.

Amit adds, "When examining the drop URLs, four of the domain names in use are not registered – yet! However, one of them is not new in relation to SpyEye - the domain ‘124ffsaf.com’, and has actually been ‘hopping’ around different IPs in several locations around the world. This attack, at the moment, is yet to gain momentum but that’s just a matter of time. This is a very real early warning and I'm pretty sure it’s only just started. I’m tempted to say ‘to be continued…’

"What makes all of this so scary is that the application is not visible on the device’s dashboard, making it virtually undetectable, so users are not aware of its presence and will struggle to get rid of it.

"Organisations and individuals need to act now and protect themselves as this variant has traits to become a more serious threat. My advice is to install a desktop browser security solution as part of a multi layered security approach."


Related Groups
Banking / Finance / Credit
Computer Hardware / Software
CRM
Performance
Security
Technology

Related News
Trusteer Receives Medal at UK IT Industry Award
Underground Call-centre for Identity Theft Uncovered
Apply Security Online to Protect Yourself Offline
NEFCU Selects Trusteer to Meet New FFIEC Security Guidelines
Trusteer Discovers New Worm-Based Financial Malware
First Data Selects Trusteer to Help Financial Institutions Comply with Banking Security

About Trusteer:
Trusteer offers solutions for financial institutions, home users, and businesses. Financial institutions use Trusteer services to secure their customers' browsers from financial malware attacks and fraudulent websites. Trusteer allows financial institutions to proactively protect against attacks that target customers directly. In addition, Trusteer allows financial institutions to receive immediate alerts, and to report whenever a new threat is launched against them or their customers. Using Trusteer, financial institutions can investigate new zero day threats, suspicious computers, and reconnected infected computers.

More Editorial from Trusteer
Trusteer Rapport Named Best Fraud Prevention Solution
Trusteer Receives Medal at UK IT Industry Award
Underground Call-centre for Identity Theft Uncovered
Apply Security Online to Protect Yourself Offline
NEFCU Selects Trusteer to Meet New FFIEC Security Guidelines
Trusteer Discovers New Worm-Based Financial Malware

Date Published: Tuesday, September 20, 2011
Printer Friendly Version Printer friendly version
 Recommend to a friend
 Bookmark & Share



Post Message

Post Message






 

 

 





-Back To Top-

| Request Information from CRM & Contact Center Suppliers | About ContactCenterWorld |
| Advertise CRM & Contact Center Solutions | Link to this site |
| Submit CRM and Contact Center Content | Contact Us | Privacy Policy |
| Recommend this site to other CRM & Contact Center Professionals | Disclaimer |

©ContactCenterWorld.com 1999-2011
The Global Support Organization For Contact Center Professionals & the place for information on:
Offshore Outsourcing, On Hold, Outsourcing, Predictive Dialers, Quality Monitoring, Recruitment, Self Service, Speech Recognition, Telemarketing, Virtual Contact Center, VoIP, Web Chat, Work at Home, Workforce Management, ACD's, Address Management, Assessment Solutions, Attrition