Critical.
Authoritative.
Strategic.
Subscribe to CIO Magazine »

Symbian malware takes money from phone

Kaspersky Lab warns that a new mobile-phone Trojan spotted in Indonesia uses SMS messages to steal money.

Hackers have discovered a new way to steal your money: texting it out of your phone.

Security vendor Kaspersky Lab says it has spotted new variants of a Trojan horse program that do just that, by taking advantage of a feature that lets mobile-phone users in Indonesia use SMS (Short Message Service) text messages to transfer money in their mobile accounts from one phone to another.

The software is a variant of the Trojan-SMS.Python.Flocker malware, originally written by Russian fraudsters. This software had been used to sign unwitting victims up for expensive mobile services such as ringtones, presumably with the program's authors getting a healthy kickback. "It seems like some Indonesian guys had a look at this stuff and thought, 'Hey, we could do this in Indonesia,'" said Roel Schouwenberg, an antivirus researcher with Kaspersky.

For the attack to work, the victim must first be tricked into downloading the Python.Flocker program onto a Symbian-based mobile phone. Once installed, the software uses a feature available to Indonesian mobile-phone users that lets them send a short SMS message to another subscriber that transfers the money into their account. The Trojan transfers the equivalent of between US$0.45 and $0.90, depending on which version of the program is installed.

The Symbian operating system is used in phones made by Nokia, Motorola, Samsung and Sony Ericsson, among others.

Criminals have created banking Trojans for the PC that silently transfer money during online banking sessions, but this is the first time Schouwenberg has seen this type of behavior on a mobile phone.

Schouwenberg did not know which Indonesian mobile service provider was targeted in this attack.

Join the CIO Australia group on LinkedIn. The group is open to CIOs, IT Directors, COOs, CTOs and senior IT managers.

More about: Ericsson, Kaspersky, Kaspersky Lab, Motorola, Nokia, Samsung, Sony, Sony Ericsson, Symbian
References show all

Comments

Post new comment

The content of this field is kept private and will not be shown publicly.
Users posting comments agree to the CIO comments policy.
Login or register to link comments to your user profile, or you may also post a comment without being logged in.
Related Coverage
Related Whitepapers
Latest Stories
Community Comments
Tags: malware, security, symbian
Latest Blog Posts
Whitepapers
  • Optimizing Storage and Protecting Data with Oracle Database 11g
    This paper focuses on key Oracle Database 11g capabilities that help IT departments better optimise their storage infrastructure, enabling administrators to deliver a cost-effective, scalable data management platform that is easy to manage, reduces costs, and protects data while continuing to deliver the performance and availability that today’s businesses require.
    Learn more »
  • Optimised Data Protection for VMware® Environments with Symantec NetBackup™ Appliances
    VMware® remains the most widely deployed virtualisation solution. The explosive growth of VMware infrastructure in organisations both large and small has enabled corporations to more fully exploit their hardware investments. With multiple virtual machines running on few physical hardware nodes, hardware costs are reduced, as well as space, power, and cooling requirements. This white paper discusses in more detail how VMware environments can be protected with the NetBackup appliances. Read more.
    Learn more »
  • Look both ways - Protecting your data with content inspection
    Today’s threat environment is as dynamic as the business world in which we operate. As the communications channels we use continue to proliferate and evolve, so too have the vulnerabilities. Finding the right balance between ensuring the security of sensitive data, enabling the free flow of information and making full use of the latest web-based technologies can be a challenge. Deep content inspection is a vital layer in any unified information security strategy, helping organisations to take control over their information assets while proactively protecting against malware and data leakage. Read on.
    Learn more »
All whitepapers
rhs_login_lockGet exclusive access to Invitation only events CIO, reports & analysis.
Recent comments