Subscribe / Unsubscribe Enewsletters | Login | Register

Pencil Banner

SMS stealing apps uploaded to Google Play by Carberp banking malware gang

Lucian Constantin | Dec. 17, 2012
Several malicious Android apps designed to steal mobile transaction authentication numbers (mTANs) sent by banks to their customers over SMS (Short Message Service) were found on Google Play by researchers from antivirus vendor Kaspersky Lab.

"It seems that it's not that hard to bypass Google Play's defenses because malware continues to appear there regularly," Maslennikov said via email.

Bogdan Botezatu, a senior e-threat analyst at antivirus vendor Bitdefender, believes that it might be hard for Google's Bouncer to detect ZitMo, SpitMo or CitMo components because they are functionally similar to some legitimate applications.

"The mobile version of the Trojan is only responsible with hijacking the received SMS and forwarding its contents to a different recipient, and this behavior is also found in legitimate applications, such as SMS management apps or even applications that allow the user to remotely control their devices via SMS in the event they get stolen or lost," he said via email. "SMS interception is a feature that is well documented on forums, along with sample code. If the same sample code is used both in malicious and legit applications, it would be even harder to detect and block."

The ability to use Google Play to distribute SMS stealing apps offers advantages to cybercriminals, Botezatu said. First of all, some user devices are configured to only install apps obtained from Google Play. Also, users are generally less suspicious of apps downloaded via Google Play and pay less attention to their permissions because they expect the applications to be what their descriptions claim they are, he said.


Previous Page  1  2 

Sign up for Computerworld eNewsletters.