
If you happen to be among the many Symbian S60 phone users then beware. Researchers from various security firms have discovered a new mobile threat that targets Symbian phones. The worm features a signed Symbian certificate and propagates by sending malicious links via SMS to all numbers in a phone’s memory.
F-Secure characterizes this mobile malware as a Trojan because of its data stealing capabilities and the social engineering techniques employed by its creators. The malicious application is signed with a certificate that Symbian accepts, thus avoiding arising suspicions from the users.
With the appearance of this worm, the concept of mobile botnets is not just theory anymore, as Guillaume Lovet, senior manager of Fortinet’s Threat Research Team explains. “As far as our analysis goes, the worm currently does not take commands from the remote servers it contacts. However, since the copies hosted on the malicious servers are controlled by the cyber criminals, they may update them whenever they want, thereby effectively mutating the worm, adding or removing functionality. We’re really at the edge of a mobile botnet here,” he warns.
The malware attempts to hide its traces by running under the process name of “EConServer.exe,” a twist on the name of the legit “EComServer.exe” application. If the Symbian Application Manager is available, the worm can simply be uninstalled as any other piece of software. However, this might not be the case, as it attempts to kill the AppMngr process along with others that might be used to identify it, such as ActiveFile, TaskMan, TaskSpy or Y-Tasks.
This is the second serious mobile threat that we have reported this year, along with the credit stealing Trojan-SMS.Python.Flocker discovered by Kaspersky Labs and its later variant for the J2ME platform, called Trojan-SMS.J2ME.GameSat.a.
(Source) Softpedia
Popularity: 1% [?]
Tags: application manager, botnets, cyber criminals, malicious application, malware, symbian application, symbian phones, symbian s60 phone, taskspy