Jul15
6:38 am (UTC-7)   |   by Jonathan Leopando (Technical Communications)

Conventional wisdom has it that mobile platforms like PDAs and mobile phones are safer from malware attacks, one reason being the relatively closed nature of such platforms. In some platforms, such as newer versions of the Symbian OS, this is enforced in part by mandatory code signing, which requires that applications need to be signed by a third party, ensuring (in theory) that they are not malicious. (Currently, this process is carried out by Symbian Signed, now part of the Symbian Foundation).

Assuming that the third party is trustworthy, this system should be foolproof, shouldn’t it?

Not always.

In the past few days, Trend Micro has encountered a new threat for Symbian devices, deteted as SYMBOS_YXES.B. According to Marianne Mallen, Escalation Engineer in TrendLabs, it posts as the legitimate application ACSServer.exe and calling itself Sexy Space, it steals the user’s subscriber, phone, and network information, and connects to a website in order to send the said information. In addition, it can also send spammed SMS messages to the user’s contacts. (The content in the said messages is acquired from the website it connected to earlier.)

In short, it appears to be a botnet for mobile phones. All this would be worrying enough, but there’s an even bigger issue at play here. Both SYMBOS_YXES.B and an earlier variant, SYMBOS_YXES.A are signed programs. The signing process—undertaken by the Symbian Foundation itself—is supposed to ferret out instances like this, but somehow this slipped through. It may well be a coincidence, but it does not reinforce confidence in the signing system.

Whatever the case, this particular threat is already detected by the Smart Protection Network.

If you're new here, you may want to subscribe to our RSS feed. Thanks for visiting!




16 Responses to “Signed Malware Coming To A Phone Near You?”

Trackbacks

  1. Is SMS/Text Spam the New Equalizer for Cell Phone Subscribers? | Firecracker PM
  2. TrendMicro (TrendMicro)
  3. rik_ferguson (Rik Ferguson)
  4. tonys3kur3 (Tony Bradley)
  5. Afecta a Symbian nuevo malware | bSecure
  6. jrimer2008 (Jared Rimer)
  7. Afecta a Symbian nuevo malware | Netmedia.info
  8. DeclanmWaters (Declan Waters)
  9. nukeitdotorg » Trend Micro discovers mobile botnet affecting Symbian devices
  10. исследователи обнаружили ботнет из мобильных телефонов | Все новости виртуального мира
  11. Tech Thoughts Daily Net News – July 19, 2009 « Bill Mullins’ Weblog – Tech Thoughts
  12. SYMBOS_YXES.B (Sexy Space): Symbian-Signed Trojaner im Umlauf | Symbian60.mobi
  13. Symbian Signed Trojan out in the Wild - SYMBOS_YXES.B (Sexy Space)
  14. Smartphone the new target for hackers. | What Is Wrong With The World Today
  15. Доверяй, но проверяй | ДайСлово!
  16. Sexy Space becomes the first SMS-based mobile botnet - Javelin Strategy & Research Blog

Leave a Reply



© Copyright 2009 Trend Micro Inc. All rights reserved. Legal Notice