Mobile malware: a myth buster

October 2011 Information Security

Amit Klein, Trusteer CTO, explodes the myths and dispels the fantasies of mobile malware.

We are all wise to the risks our online antics pose to our security. We have learned not to trust e-mails from Nigerian Bankers offering to share millions in exchange for a small upfront handling fee. Our banks have not monitored fraudulent activity so they do not need us to verify our account details by confirming our information. Messages from DHL with attachments informing us about deliveries we are not expecting do not fool us into opening the document. We are even wise to the links in e-mails that want us to visit websites and win prizes. Why do they not work? Because we have learned the hard way.

When these scams first started circulating people fell for the lies. Some of you will remember, or heard about, the chaos caused in 2000 when people opened an attachment to find out who loved them and spread the I Love You worm. In a single day it travelled around the world causing an estimated $5,5 billion in damages.

So, why are people not heeding the warning that malware has gone mobile and taking steps to protect themselves? The reality is there is a false sense of security surrounding mobile use, especially as victims currently are few and far between, but I am here to dispel the myths and banish the fantasy.

Myth one: Mobile operating systems are sandboxed, so we are safe

Anyone that still believes this is true is living in fantasy land. We have already seen malware that attacks sandboxing – DroidDream is just one that recently made the headlines. It exploited a vulnerability in the android operating system and obtained root privileges, downloading and installing additional arbitrary pieces of software, to assume virtually limitless control of the infected smartphone.

Myth two: Mobile applications are controlled – Apple and Google are watching our backs

Anyone that still believes this myth has a serious case of loyalty overload. DroidDream was found in applications that were being sold through the Google app store proving that the semi-closed, or walled garden, approach that is supposed to protect our mobile devices and prevent malware from infecting the device is flawed.

The simple reason is Google et al want, and actively encourage, developers to create apps with just a $25 entry fee. It is unsurprising that malware writers and spammers are happy to flex their muscles and get a piece of the action. Rogue developers all too easily can get permission or approval to upload their infected applications – that is what they did with DroidDream.

Myth three: There is no money in mobile malware so fraudsters are not interested

Wake up people – we are already in the middle of a third generation of financial malware. Zero generation had users unwittingly dialling premium numbers or sending SMS texts to services that charged them for the privilege

First generation was malware that engaged simple tricks, for example changing the host file of an infected device and redirecting the user’s mobile browser to a phishing site.

Second generation has seen malware increasingly infect the mobile device that works in conjunction with malware already infecting the desktop. In case you are not sure how this scam works, basically malware infects the mobile device and steals SMS verification messages and reroutes them to the fraudster.

The next generation of mobile malware will actually attack the mobile device focusing on mobile browsers or mobile applications themselves to abuse the current users session and commit fraudulent transactions, possibly even with the unintended aid of the user. While at the moment, this could be argued as myth it will not be long before it becomes reality, we are just waiting for banks to introduce the service. Fraudsters have all the tools they need to effectively turn mobile malware into the biggest customer security problem we have ever seen. They are lacking one thing – customer adoption.

I said at the start of this article that people need to heed the warning that malware has gone mobile and taking steps to protect themselves. As I am sure you will agree, I have proven it is not only possible but is happening, so it is time to start affording your smartphone the same protection you do the PC.

www.trusteer.com





Share this article:
Share via emailShare via LinkedInPrint this page



Further reading:

Highest increase in global cyberattacks in two years
Information Security News & Events
Check Point Global Research released new data on Q2 2024 cyber-attack trends, noting a 30% global increase in Q2 2024, with Africa experiencing the highest average weekly per organisation.

Read more...
Cybersecurity a challenge in digitalising OT
Kaspersky Information Security Industrial (Industry)
According to a study by Kaspersky and VDC Research on securing operational technology environments, the primary risks are inadequate security measures, insufficient resources allocated to OT cybersecurity, challenges surrounding regulatory compliance, and the complexities of IT/OT integration.

Read more...
Cybersecurity in South Africa
Information Security
According to the Allianz Risk Barometer 2025, cyber incidents, including ransomware attacks, data breaches and IT outages, are now the top global business risk, marking their fourth year at the top.

Read more...
Are AI agents a game-changer?
Information Security
While AI-powered chatbots have been around for a while, AI agents go beyond simple assistants, functioning as self-learning digital operatives that plan, execute, and adapt in real time. These advancements do not just enhance cybercriminal tactics, they may fundamentally change the battlefield.

Read more...
Disaster recovery vs cyber recovery
Information Security
Disaster recovery centres on restoring IT operations following events like natural disasters, hardware failures or accidents, while cyber recovery is specifically tailored to address intentional cyberthreats such as ransomware and data breaches.

Read more...
Back-up securely and restore in seconds
Betatrac Telematic Solutions Editor's Choice Information Security Infrastructure
Betatrac has a solution that enables companies to back-up up to 8 TB of data onto a device and restore it in 30 seconds in an emergency, called Rapid Access Data Recovery (RADR).

Read more...
The rise of AI-powered cybercrime and defence
Information Security News & Events AI & Data Analytics
Check Point Software Technologies launched its inaugural AI Security Report, offering an in-depth exploration of how cybercriminals are weaponising artificial intelligence (AI), alongside strategic insights defenders need to stay ahead.

Read more...
The deepfake crisis is here and now
Information Security Training & Education
Deepfakes are a growing cybersecurity threat that blur the line between reality and fiction. These AI-generated synthetic media have evolved from technological curiosities to sophisticated weapons of digital deception, costing companies upwards of $600 000 each.

Read more...
What does Agentic AI mean for cybersecurity?
Information Security AI & Data Analytics
AI agents will change how we work by scheduling meetings on our behalf and even managing supply chain items. However, without adequate protection, they become soft targets for criminals.

Read more...
Phishing attacks through SVG image files
Kaspersky News & Events Information Security
Kaspersky has detected a new trend: attackers are distributing phishing emails to individual and corporate users with attachments in SVG (Scalable Vector Graphics) files, a format commonly used for storing images.

Read more...