Mobile virus
New mobile viruses are built by highly organised criminals

Mobile phone viruses gathering pace

But analyst claims problem is a 'raindrop in a thunderstorm'

Written by Ian Williams

Mobile antivirus firm UMU claims to have demonstrated how easy it is to infect a mobile device with malware. 

The company took a standard Nokia 6330 mobile phone to British high streets and shopping centres, and opened up the device to several mobile phone viruses simply by turning on its Bluetooth receiver or downloading files via MMS, SMS or email.

UMU identified five types of viruses and the average number of times these viruses infected the phone across a 28-day period:

Cabir (1) - spread via Bluetooth and MMS, it does not directly damage the phone but continually tries to detect other devices to infect, greatly reducing battery life.

CommWarrior (2) - spread as above, it resets the phone on 14th of every month deleting all personal data.

Skulls (1) - downloaded by user, it disables phone applications like phone book, SMS, media player and changes all phone icons to a skull and crossbones leaving it unusable.

CardTrap (2) - spread as above, it overwrites applications such as the phone book with corrupted copies. These applications will no longer work when you next reboot the phone, rendering the phone useless. It also drops installers for Skulls, CommWarrior and Cabir onto the device and puts some Windows viruses onto the memory card so that plugging the memory card into a PC will result in the PC being infected as well

Doomed (1) - spread as above, it disables some applications and attempts to prevent the phone from restarting as well as installing Cabir, CommWarrior, Fontal, CardTrap, CardBlock and Skulls. It can also sometimes cause other Bluetooth devices in the vicinity of the infected device to restart

In some cases, the Nokia handset was infected by malware which, once downloaded, could allow the hacker to monitor calls, emails and texts, steal private data, send that data to others in the user's address book and even dial premium rate numbers at the user's expense.

Peter Harrison, chief technology officer at UMU, said: "The new breed of viruses is the most malicious we have ever seen. They are built by highly organised criminals, intent on causing widespread damage or extracting maximum commercial gain.

"What is really scary is that lots of people may already be infected and not know it. Our monitoring has shown a sustained spike in malware detections this year, and there are currently 300 viruses for smartphones.

"And with over 100 million smartphones now in existence it won't be long before they spread."

However, Graham Cluley, senior technology consultant at Sophos, described the problem as a "raindrop in a thunderstorm".

Although businesses should be considering how to control data on mobile devices, Cluley believes that the problem of sensitive data being leaked by leaving mobile devices unattended and unprotected is of much greater concern than mobile malware.

The security expert explained that the effort involved in creating and spreading these programs is not financially viable compared to targeting PC users.

Cluley suggested that users should use common sense when it comes to opening the device to outside communications and installing unknown applications in much the same way as they would with a PC.

Tags:

reader comments

related articles

Infosecurity Europe 2007

Mobile viruses may be underreported

Network operators may be keeping quiet on scale of problem 26 Apr 2007

 

Microsoft floats Deepfish mobile browser

Software allows mobiles to view full web pages 30 Mar 2007

Consumers fail to check out mobile banking

Analyst finds 'limited interest' in mobile phone-based offerings 24 Apr 2007

Spammers trash anti-money laundering site

With a little help from the hosting company 12 Oct 2007

Firms urged to tackle email data leaks

Half of employees have sent emails to the wrong person 19 Nov 2007

Spam Pledge calls for end to junk email

Thirty years is enough, says Sophos 01 May 2008

related whitepapers

today's top stories

Why the ‘e’ in e-Crime?

This week the Home Office announced the creation of the new Police Central e-crime Unit (PCeU). The PCeU promises to tackle cyber... 02 Oct 2008

National Identity Fraud Prevention Week

Every Monday seems to mark the beginning of a new awareness drive and this week’s theme has particular importance to small businesses... 06 Oct 2008

Wanted: a viable model for fibre

While other European countries are pressing ahead with fibre rollouts, progress in the UK is being held back as the debate over who will foot the bill drags on, writes Dave Bailey 02 Oct 2008

ITIL tools add lustre to Technicolor helpdesk

Centralising IT support helped to improve the service to 6,000 users in 58 locations at the film processing firm 02 Oct 2008

Computing podcast - Next-generation broadband Britain; and we report from Gartner's IT security summit

In our latest podcast, we discuss the hurdles that a national fibre-optic network must overcome, and look at the issues discussed at the recent IT security conference 02 Oct 2008

Advertisement

Newsletter signup

Sign up for our range of FREE newsletters:

Existing User

Newsletter user login:

Jobs

Related jobs

Job of the week

Job alerts

Sign up here

Find your next job

Advertisement

White papers

Search white papers

Top categories

VPN, Extranet and Intranet Solutions

WAN/ LAN Solutions

Network Security

Interoperability-Connectivity

Grid/ Utility Computing

Latest poll

Who should pay for the rollout of next-generation broadband?

Who should pay for the rollout of next-generation broadband?

A UK high-speed fibre network could cost up to £30bn - who should fund it?

Previous poll results

Latest audio and video articles

Podcast imageAudio

Computing podcast - Next-generation broadband Britain; and we report from Gartner's IT security summit

In our latest podcast, we discuss the hurdles that a national fibre-optic network must overcome, and look at the issues discussed at the recent IT security conference 02 Oct 2008

Ethernet cableVideo

Is high-speed Ethernet ready to roll?

What are the prospects for the next generation of the networking technology? 26 Sep 2008

Latest in-depth articles

Basketball player performing a slam dunkFeatures

Agility brings results - innovation in software development

Companies are increasingly moving away from rigid programming methodologies and adopting more agile approaches that aim to deliver small gains in rapid succession 01 Oct 2008

Co-op storeAnalysis

Computing Awards: Innovative project of the year shortlist

As part of our build-up to the Computing Awards for Excellence, which take place at London’s Battersea Park events arena on 5 November, we turn the spotlight on the nominations for Innovative Project of the Year 01 Oct 2008

Advertisement

Primary Navigation