| Forums | Active Topics | [Click to Join Our Forums] | Cell Tower Pictures | FAQ | Search | Today's Posts | Mark Forums Read |
|
| | LinkBack | Thread Tools | Search this Thread |
| | #1 |
| Easy,Cheap & Sleazy Join Date: Sep 2002 Location: Union County NJ Posts: 8,457
Phone(s): EnV, V750 Provider(s): Verizon Thanks: 2
Thanked 1 Time in 1 Post
Images: 293 |
URL: http://news.zdnet.com/2100-1009_22-5460194.html Virus writers are targeting Symbian-based cell phones with a Trojan horse that kills off system applications and replaces their icons with images of skulls. The program, dubbed "Skulls" by antivirus companies, is disguised as a theme manager for Nokia phones in the Symbian Installation System format, said Mikko Hypponen, director of antivirus research for software Photo: F-Secure The Skulls Trojan horse changes system icons, disabling all but phone functions. maker F-Secure. Only a few people have managed to run across the program on the Web and then downloaded and run the Trojan horse, he said. "We are not talking about a huge amount of infected people, and it is not a virus, so it is not spreading," Hypponen said. The program is the latest threat to affect mobile phones and PDAs. Earlier this month, a program called Delf infected PCs in order to send spam to mobile phone users in Russia. Two other malicious programs--Mosquito and Cabir--were also aimed at infecting phones that use the Symbian operating system. The creators of Cabir even created a version that attempts to infect Windows CE devices. Like the latest threat, none of the cell-phone attacks have yet amounted to much. When run, the Skulls program breaks all the links to Symbian system applications and replaces the icons with images of skulls. Third-party applications are not affected, Hypponen said, allowing users that have installed a non-Symbian file manager to actually find and delete the malicious program files, cleaning the phone. For users that have no third-party file manager, the only current fix appears to be a hard reset, which will leave the phone in its default factory condition. Unfortunately, this fix will also delete any user data. "In practice, it is difficult to clean the phone," Hypponen said. "You can't go online, you can't download fixing programs, you can't beam anything to the phone." While the program can cause some headaches, it is not a significant threat. Still, it is a signpost indicating the direction that virus writers could be headed, said Vincent Weafer, senior director for security response at Symantec, a maker of antivirus software. "It does no permanent damage," he said. "But it does mean that people are investing time in investigating the possibilities" for infecting and damaging mobile phones, he said. |
| | |
| | #2 |
| Droid you're looking for Join Date: Oct 2003 Location: Chili Town Posts: 6,705
Phone(s): a855 (pending,) V3t, v620 Provider(s): Voicestream Wireless Devices: Motorola S805, Motorola HS350, Apple MacBook Thanks: 3
Thanked 11 Times in 8 Posts
Images: 21 |
Great... just what we need. Don't people have better things to do with their time?
__________________ iDon't but Droid does. |
| | |
| | #3 |
| Mobile Enthusiast Join Date: Sep 2004 Location: Los Angeles, CA Posts: 5,878
Phone(s): LG Voyager, Nokia 6263 Provider(s): Verizon Wireless, T-Mobile. Formerly AT&T, Nextel Devices: 80gb iPod, Dell laptop Thanks: 82
Thanked 59 Times in 58 Posts
|
__________________ Started with PacTel Cellular (1994) which became AIRTOUCH (1994-2000) which became verizonwireless (2000-present). Back with -T- Mobile (2004-2009, 2009-present) |
| | |
| | #4 | |
| Iowa Cellular Guru Join Date: Sep 2003 Location: SID 150 or 1214 Posts: 3,472
Phone(s): Nokia 6256i, (retired) Motorola V120c, Timeport 270c, Nokia 252 (Airtouch) Provider(s): Verizon Wireless Thanks: 0
Thanked 0 Times in 0 Posts
| Quote:
| |
| | |
| | #5 |
| Euer WA Experte in Europa Join Date: Jan 2003 Location: 94065,US/Köln, Germany Posts: 6,568
Phone(s): HTC/T-Mobile MDA II PPC, Motorola E770V Provider(s): E-Plus (BASE 12 month flatrate)/Vodafone Germany Devices: T-Mobile MDA II - GSM 900/1800/1900 w/WM 2003 Thanks: 0
Thanked 0 Times in 0 Posts
Images: 419 |
Even with such viruses being developed to target the Symbian OS, it's not as annoying to have something like this on your phone whereas it's a lot easier to get a virus on one's computer.
__________________ Visiting Europe?Ask me: http://forums.wirelessadvisor.com/international-wireless-forum-including-canada-mexico/ http://forums.wirelessadvisor.com/international-wireless-forum-including-canada-mexico/8351-europe-sim-info-helpful-links.html Nokia Reset Codes: http://forums.wirelessadvisor.com/nokia/7973-nokia-series-40-60-80-reset.html Originally from: Redwood City, CA Living in: Cologne, Germany |
| | |
| | #6 | |
| Technology Aficionado Join Date: Jul 2003 Location: The Florida Everglades Posts: 8,553
Phone(s): HTC Touch Pro2 (me), Moto Adventure V750 (dad), Moto E815 (mom), LG Chocolate 3 (sis) Provider(s): Verizon (4 lines on a FS plan); AT&T (past) Devices: NB;GPS;Slingbox PRO;iPod 80GB;Kenwood DDX512 Thanks: 10
Thanked 10 Times in 7 Posts
Images: 68 | Quote:
Plus, unless the user knows what they are doing, they need to get the latest updates for their virus scanner program by connecting to the company's server. I'm glad I don't have a phone that runs on the Symbian system.
__________________ My Carriers: Cellular One (TDMA) [1998-1999]>>AT&T (TDMA) [1999-2001]>>Cingular (TDMA) [2001-2003]>>Sprint [2003-2005]>>Verizon Wireless [2005 to 2008]>>Sprint SERO [2006-2008]>>AT&T [2008 to present]>>Verizon Wireless INpulse [2009 to present] | |
| | |
| | #7 |
| Euer WA Experte in Europa Join Date: Jan 2003 Location: 94065,US/Köln, Germany Posts: 6,568
Phone(s): HTC/T-Mobile MDA II PPC, Motorola E770V Provider(s): E-Plus (BASE 12 month flatrate)/Vodafone Germany Devices: T-Mobile MDA II - GSM 900/1800/1900 w/WM 2003 Thanks: 0
Thanked 0 Times in 0 Posts
Images: 419 |
Correct but even with viruses around, I'm not too concerned about my Symbian OS phone since I don't upload games to it as much.
__________________ Visiting Europe?Ask me: http://forums.wirelessadvisor.com/forumdisplay.php?f=10 http://forums.wirelessadvisor.com/showthread.php?t=8351 Nokia Reset Codes: http://forums.wirelessadvisor.com/showthread.php?t=7973 Originally from: Redwood City, CA Living in: Cologne, Germany |
| | |
| | Original Poster
#8 |
| Easy,Cheap & Sleazy Join Date: Sep 2002 Location: Union County NJ Posts: 8,457
Phone(s): EnV, V750 Provider(s): Verizon Thanks: 2
Thanked 1 Time in 1 Post
Images: 293 |
I saw an article yesterday saying there is a new varient of this virus out & one way of it transfering is thru BT, I will see if i can find the article.
|
| | |
| | #9 |
| Euer WA Experte in Europa Join Date: Jan 2003 Location: 94065,US/Köln, Germany Posts: 6,568
Phone(s): HTC/T-Mobile MDA II PPC, Motorola E770V Provider(s): E-Plus (BASE 12 month flatrate)/Vodafone Germany Devices: T-Mobile MDA II - GSM 900/1800/1900 w/WM 2003 Thanks: 0
Thanked 0 Times in 0 Posts
Images: 419 |
Ok so it takes advantage of someone sending something through BT then? It's not something which activates BT without your knowledge and starts sending stuff?
__________________ Visiting Europe?Ask me: http://forums.wirelessadvisor.com/forumdisplay.php?f=10 http://forums.wirelessadvisor.com/showthread.php?t=8351 Nokia Reset Codes: http://forums.wirelessadvisor.com/showthread.php?t=7973 Originally from: Redwood City, CA Living in: Cologne, Germany |
| | |
| | Original Poster
#10 |
| Easy,Cheap & Sleazy Join Date: Sep 2002 Location: Union County NJ Posts: 8,457
Phone(s): EnV, V750 Provider(s): Verizon Thanks: 2
Thanked 1 Time in 1 Post
Images: 293 |
Here is the Article I found about the 2nd version. This story from ZDNet News, located at http://news.zdnet.com. -------------------------------------------------------------- Matt Hines URL: http://news.zdnet.com/2100-1009_22-5469691.html Virus writers have unleashed a second version of the "Skulls" Trojan horse and packaged it with a cell phone virus, a security company has warned. The hybrid Skulls.B Trojan horse displays images of skulls instead of the program icons on handsets running the Symbian operating system, software maker F-Secure said in an advisory Monday. It also releases the Cabir.B worm, the company said. Cabir, which asks its victims if they would like to be infected, was thought to be a proof-of-concept virus when it was released earlier this year. The virus spreads by sending itself to other handsets within Bluetooth broadcasting range. Phones infected with the Skulls.B hybrid can infect nearby handsets with Cabir. The Trojan horse, though, can only be downloaded and does not spread using Cabir as a vehicle. Skulls was originally distributed on Symbian shareware Web sites as "Extended Theme Manager." When infected with Cabir, a phone displays the word "Caribe" on a screen as the worm modifies the Symbian operating system and looks for other cell phones to target. F-Secure said that cell phones from manufacturers such as Nokia, Siemens, Panasonic and Sendo were vulnerable. It has posted advice on disinfecting cell phones on its Web site. But Symbian has said in the past that the Trojan horse only affects mobile phones running Nokia's Series 60 software. The software developer could not be immediately reached for comment. Mikko Hypponen, director of antivirus research at F-Secure, said that Skulls represents only a mild threat to mobile device users at this point, based on its Trojan horse design. But he said the program is indicative of a growing effort among virus writers to target wireless handsets. "Obviously what we're seeing here are the early days of a new platform, with the bad guys trying to find different ways to attack (cell phones) and test out different technologies," Hypponen said. "Skulls' existence shows that there is increasing activity in the underground looking at phones and genuine interest in how to write Trojans, backdoors and viruses for these devices." In addition to creating something of a template for future mobile device viruses, Hypponen said that Skull's existence highlights the fact that phones may be more vulnerable to attacks than other devices, based on their direct ties to systems that deal with purchases and other transactions. "The biggest difference from PC viruses to phone applications are the direct links to money," he said. "If you can infect a phone you can immediately begin making calls or sending text messages to toll numbers in order to steal from someone. The theft will happen a lot faster than it did with PCs." |
| | |
| | #11 |
| Euer WA Experte in Europa Join Date: Jan 2003 Location: 94065,US/Köln, Germany Posts: 6,568
Phone(s): HTC/T-Mobile MDA II PPC, Motorola E770V Provider(s): E-Plus (BASE 12 month flatrate)/Vodafone Germany Devices: T-Mobile MDA II - GSM 900/1800/1900 w/WM 2003 Thanks: 0
Thanked 0 Times in 0 Posts
Images: 419 |
Why does Nokia always get caught with this kind of thing? Symbian is mostly their baby, let's hope they will make some major improvements once S60 Version 2 is released.
__________________ Visiting Europe?Ask me: http://forums.wirelessadvisor.com/forumdisplay.php?f=10 http://forums.wirelessadvisor.com/showthread.php?t=8351 Nokia Reset Codes: http://forums.wirelessadvisor.com/showthread.php?t=7973 Originally from: Redwood City, CA Living in: Cologne, Germany |
| | |
| Currently Active Users Viewing This Thread: 1 (0 members and 1 guests) | |
| Thread Tools | Search this Thread |
| |
| | ||||
| Thread | Thread Starter | Forum | Replies | Last Post |
| Virus Emails NOT from WA | JFB | The WirelessAdvisor Community | 42 | 10-13-2005 1:29 PM |
| New Symbian cellphone Virus | Fire14 | Wireless News | 2 | 01-18-2005 5:17 PM |
| Virus/Worm Information | MOTOhooligan | GENERAL Wireless Discussion | 0 | 11-15-2004 12:36 PM |
| First mobile phone virus created | Bugwart | Wireless News | 13 | 06-18-2004 2:12 PM |
| T720 Virus? | NeoDigital | MOTOROLA | 13 | 12-23-2002 6:54 PM |