First SpyEye Attack on Android Mobile Platform is Virtually Undetectable
Trusteer intelligence has spotted the first SpyEye variant, called SPITMO, attacking Android devices in the wild. According to Amit Klein, Trusteer’s chief technology officer, the threat posed by DriodOS/Spitmo has escalated the danger of SpyEye now that this malicious software has been able to shift its delivery and infection methods.
Amit clarifies, "We always said it was just a matter of time before the true potential of SpitMo was realised. When it first emerged back in April F-Secure reported, in its blog, that it was targeting European Banks. The trojan injected fields into a bank's webpage asking the customer to input his mobile phone number and the IMEI of the phone. The fraudster then needed to follow a cumbersome three stage sequence - get the IMEI number; generate a certificate; then release an updated installer. This process could take up to three days.
"We couldn’t believe fraudsters would go to that much effort just to steal a couple of SMSs - and it appears we were right. Information gathered by Trusteer's Intelligence Centre has discovered a new far more intuitive, and modern, approach of SPITMO for Android now active in the wild."
SPITMO – Moving on to Android
Looking at the attack vector in action, Amit explains, "When a user browses to the targeted bank a message is injected presenting a "new" mandatory security measure, enforced by the bank, in order to use its online banking service. The initiative pretends to be an Android application that protects the phone’s SMS messages from being intercepted and will protect the user against fraud. How’s that for irony!"
Once the user clicks on "set the application" they are given further instructions to walk them though downloading and installing the application.
To complete the installation, the user is instructed to dial the number "325000"; the call is intercepted by the Android malware and an ‘alleged’ activation code is presented, to be submitted later in to the "bank’s site". Besides concealing the true nature of the application, this "activation code" does not serve any legitimate purpose.
Once the Trojan has successfully installed, all incoming SMS messages will be intercepted and transferred to the attacker’s Command and Control server (C&C). A code snippet is run when an SMS is received, creating a string, which will later be appended as a query string to a GET HTTP request, to be sent to the attacker's drop zone. Amit adds, "When examining the drop URLs, four of the domain names in use are not registered – yet! However, one of them is not new in relation to SpyEye - the domain ‘124ffsaf.com’, and has actually been ‘hopping’ around different IPs in several locations around the world. This attack, at the moment, is yet to gain momentum but that’s just a matter of time. This is a very real early warning and I'm pretty sure it’s only just started. I’m tempted to say ‘to be continued…’
"What makes all of this so scary is that the application is not visible on the device’s dashboard, making it virtually undetectable, so users are not aware of its presence and will struggle to get rid of it.
"Organisations and individuals need to act now and protect themselves as this variant has traits to become a more serious threat. My advice is to install a desktop browser security solution as part of a multi layered security approach."
About Trusteer: Trusteer offers solutions for financial institutions, home users, and businesses. Financial institutions use Trusteer services to secure their customers' browsers from financial malware attacks and fraudulent websites. Trusteer allows financial institutions to proactively protect against attacks that target customers directly. In addition, Trusteer allows financial institutions to receive immediate alerts, and to report whenever a new threat is launched against them or their customers. Using Trusteer, financial institutions can investigate new zero day threats, suspicious computers, and reconnected infected computers.
Don't have a current membership with ContactCenterWorld.com?
become a member and connect with the rest of the Contact Center Industry at ContactCenterWorld.com here
Forum Profile
Job Title:
(Display this on the Forum)
Company:
(Display this on the Forum)
Neither the Administrators of these forums, or the Moderators participating, are responsible for the privacy practices of any user. Remember that all information that is disclosed in these areas becomes public information and you should exercise caution when deciding to share any of your personal information. Any user who finds material posted by another user objectionable is encouraged to contact us via e-mail. We are authorized by you to remove or modify any data submitted by you to these forums for any reason we feel constitutes a violation of our policies, whether stated, implied or not.
This site may contain links to other web sites and files. We have no control over the content and can not ensure it will not be offensive or objectionable. We will, however, remove links to material that we feel is inappropriate as we become aware of them.
By pressing the "Agree" button, you agree that you, the user, are 13 years of age or over. You are fully responsible for any information or file supplied by this user. You also agree that you will not post any copyrighted material that is not owned by yourself or the owners of these forums. In your use of these forums, you agree that you will not post any information which is vulgar, harassing, hateful, threatening, invading of others privacy, sexually oriented, or violates any laws.
If you do agree with the rules and policies stated in this agreement, and meet the criteria stated herein, proceed to press the "Agree" button below, otherwise press "Cancel".
If you have any questions about this privacy statement or the use of these forums, you can contact the forum administrator at: rajw@contactcenterworld.com