IT NEWS      Sustainability        - Virtualisation   
Technology news and Jobs arrow Information Technology News arrow Nokia and Symbian mobiles under attack from new worm
Nokia and Symbian mobiles under attack from new worm PDF E-mail
User Rating: / 2
PoorBest 
by Stan Beer   
Tuesday, 22 January 2008
A new SymbianOS worm has been discovered to be actively spreading on various mobile phone networks harvesting phone numbers stored in contact lists to send multimedia messages. The incident, while still relatively contained, could signal a trend to mobile phone malware exploitation that security firms have long been predicting as inevitable.

According to security firm, Fortinet, the worm, deemed SymbOS/Beselo.A!worm is able to run on several Symbian S60 enabled devices. These devices include, but may not be limited to, Nokia 6600, 6630, 6680, 7610, N70 and N72 phones.

After an installation phase, the worm engages in a propagation routine.

Phone numbers located in the contact list of the devices are harvested, and targeted by a viral MMS carrying a SIS-packed (Symbian Installation Source) version of the worm. However, the SIS file does not bear a .sis file extension -- rather, it is disguised as a multimedia file with an evocative name: either Beauty.jpg, Sex.mp3 or Love.rm.

Unlike Microsoft Windows, SymbianOS types files based on their contents and not their extensions, so it is worth noting that recipients of infected MMS would still be presented with an installation dialogue upon "clicking" on the attachment. Therefore, users could easily be deceived by the extension and unknowingly install the malicious piece of software.

In addition to harvesting the numbers stored in the phone address book as mentioned above, the Beselo worm sends itself to generated numbers as well.

Interestingly, all those numbers are located in China and belong to the same mobile phone operator. Some of those numbers have been verified to belong to actual customers, rather than being premium service numbers. The whys and hows of such a routine are still under investigation.

Users may know they have been infected if they see unrecognized sent messages in their MMS outboxes (the device needs to be configured to save such messages). FortiClient Mobile automatically detects and removes the Beselo worm. For users without FortiClient Mobile who believe they may be infected, please contact your mobile carrier or phone manufacturer for technical support in manually removing the virus.

Fortunately, the prevalence of this mobile malware incident is currently still low.

More information on SymbOS/Beselo.A!worm can be found here .

Please enable JavaScript in your browser to post your comment!


Get stories like this delivered daily - FREE - subscribe now
 
< Next story in category   Previous story in the category >
  •   *  
  • Search
  • AdvSeach
  • Login
  • Events
  • FreeStuff
Subscribe to our free e-newsletter
First name:
Last name:
Your email address:
Your role:
Your industry:
Australian state:
Country:
Enter the security code shown:
mandatory
Contact , Register , Advertise with iTWire , Links , About iTWire , Feedback , Post your jobs , Events , iTWire site map , Start Blogging , MyBlogLog page
Industry Releases , Submit your release now