Sep29 |
1:53 pm (UTC-7) | by
Karla Agregado (Fraud Analyst) |
The recent rise of mobile computing is further signaling the need for users to have good reliable mobile browsers such as Opera Mini installed in their smartphones or in any mobile device. We believe that this is why cybercriminals are currently using Opera Mobile as a mobile malware disguise.
We encountered a website that seems to have been designed to be viewed on a mobile device. The site, which is in Russian, looks like the Opera site. It immediately informs visitors that they need to upgrade their versions of Opera Mini.

All of the links in the website lead to the download of the malicious file OperaMini.jar, which Trend Micro now detects as J2ME_FAKEBROWS.A.
When executed, it checks if the mobile phone uses certain service centers then proceeds to sending text messages to premium numbers. It affects the mobile devices that support MIDlets—a Java program for embedded devices, specifically Java 2 Micro Edition (J2ME).
We’ve blocked access to the malicious site and we are currently monitoring for more related malicious activities.
Users may refer to our Threat Encyclopedia page on mobile malware for tips on keeping their mobile devices protected. They should also check out Opera’s official website, http://opera.com or http://operamini.com, if they want to install the said browser in their devices.
Update as of October 3, 2011, 4:45 AM PST
We were able to find another mobile malware that arrives as a fake Opera Mini installer. This malware, however, targets Android users. Detected as ANDROIDOS_FAKEBROWS.A, this malware is a premium service abuser, as it sends messages to premium numbers, leaving affected users with unwanted charges.
As advised, users should only install Opera Mini in their devices by directly accessing the Opera site to avoid being victimized.
Share this article |
|
14 Responses to “Mobile Malware Found Disguised as Opera Mini”
Trackbacks
- Stay safe with Opera Mini | Opera News
- Tetap aman dengan Opera Mini | Opera News
- Mobile malware masquerades as Opera Mini browser | | LANGUAGE LEARNİNGLANGUAGE LEARNİNG
- Fake Opera Mini Website Installing Mobile Malware
- 伪装为 Opera Mini 的手机恶意软件 | Opera IM
- Malware giả mạo Opera Mini. Hãy cẩn thận! | Opera News
- Detección de malware móvil disfrazado de Opera Mini » blog.trendmicro.es
- Mobile Malware Found Disguised as Opera Mini | Simply Security
- Opera Mini 6.5 Comes To Market Updated with Data Tracker
- "Rogue browsers will make a comeback on the mobile platform." | 安全业界观察
- Android malware invasion – only time can tell | Security on steroids




September 30th, 2011 at 3:17 pm
does this mean that Opera Mobile is not as safe as the Opera Mini?
October 1st, 2011 at 8:11 pm
@skry I think it’s relatively up to date. The problem is that Twitter is not exposing the real data via its API
October 17th, 2011 at 8:23 pm
thanks for the information. I do not know that a certain virus could cloak itself int a j2me app and affect j2me phones.