Current:
Trojan-SMS.Python.Flocke

Go back to
NEWS MAIN




ACCELEROMETER
section


PYTHON
section


FREEWARE
section

SF FORUM



Stay up to date
Get SF feed


Add to Google

Subscribe in NewsGator Online

[Valid RSS]

Syndicate this site




+ First Python Based Malicious Application For S60 Devices?!

22 January 2009

Reports A New Malicious Program For
S60 Phones Steals Money From Mobile Accounts

Kaspersky Mobile Security 7.0

Researchers from Kaspersky Lab, a leading developer of secure content management systems, have detected a new malicious program capable of controlling a user’s mobile phone account!

Last week, Kaspersky Lab experts detected a new malicious program for Symbian that targets customers of an Indonesian mobile phone operator.

The Trojan is written in Python, a script language. It sends SMS messages to a short number with instructions to transfer part of the money in the user’s account to another account, which belongs to the cybercriminals.

There are five known variants of Trojan-SMS.Python.Flocker: Trojan-SMS.Python.Flocker.ab, Trojan-SMS.Python.Flocker.ac, Trojan-SMS.Python.Flocker.ad, Trojan-SMS.Python.Flocker.ae, and Trojan-SMS.Python.Flocker.af.

Unfortunately Kaspersky’s report provide just a basic info with any further details and it is still not quite clear what versions of S60 platform are affected and all we know is that Trojan is currently incident is currently limited to a specific country!

Another important thing is that Trojan is written in Python which means that it can't be executed on it's own since it requires Python to be installed, so only phones with installed python application are the only possible target of this Trojan.

The amounts transferred range from $0.45 to $0.90. Thus, if the cybercriminals behind the Trojan manage to infect a large number of phones, the amount transferred to their mobile phone account as a result could be quite substantial.

"Obviously, the authors of the Trojan want to make money,” said Denis Maslennikov, a senior malware analyst at Kaspersky Lab. “It seems that the focus on financial fraud in the mobile malware industry will only get more pronounced over time.

Until recently, many people thought that malicious programs that send SMS messages without the user’s knowledge were a purely Russian phenomenon. Now we can see that the problem no longer affects only Russian users - it’s becoming an international issue."

Kaspersky Mobile Security users are protected from the new Trojan: the Kaspersky Lab product blocks malicious programs by not allowing them to run. Kaspersky Lab recommends users to exercise caution when using a smartphone to browse the Internet and to keep antivirus databases up-to-date.

Surce: Kaspersky Author: Teo


copyright © Symbian freak 2005, all rights reserved

Trademarks
All trademarks and registered trademarks are property of their respective owners.

SYMBIAN and all SYMBIAN-based marks and logos are trade marks
of Symbian Software Limited. This website is not in any way endorsed or supported by Symbian Software Limited.

NOKIA and all Nokia-based marks and logos are trade marks
of Nokia Corporation. This website is not in any way endorsed or supported
by Nokia Corporation

Google
Web
Symbian Freak

.:Related stories:.
+ Fortinet Offers Free Protection Against "Curse of Silence"
+ Mobile Virology: F-Secure Expects More Malware Attacks in 2008
+ Spanish police arrest Symbian virus writer
+ Nokia's Symbian S60 platform security has been kacked?
+ Nokia: Hacking possible but takes time
+ Mobile Virology: Kaspersky Lab presents the first part of a new analytical report
+ Calvin stinger
+ Summary Of Mobile Threats For Year 2005
+ F-secure found three new Cardtrap versions!
+ Phone book stealers
+ Mobile safety at your fingertips!!
+ Number of known Symbian trojans double in one day!!
+ Number of known Symbian trojans double in one day!!
+ Three new Symbian trojans in one day!!
.: Symbian viruses :.
+ Curse of Silence
+ Flexispy.A
+ Redbrowser.A
+ Pbstealer.A
+ Pbstealer.B
+ Pbstealer.C
+ Doomboot.A
+ Cardblock.A
+ Doomboot.A
+ Onehop.A
+ Bootton.A
+ Skulls
+ Skull.L
+ Mabir
+ Fontal.A
+ Drever.B / C
+ Mabir.A
+ Hobbes.A
+ Locknut
+ Lasco
+ Cabir
+ Cabir.AA
+ CommWarrior.C