Softpedia
 

NEWS CATEGORIES:



NEWS ARCHIVE >>
SOFTPEDIA REVIEWS >>
MEET THE EDITORS >>
TRENDING TODAY
Home > News > Security > Virus alerts

August 20th, 2012, 08:19 GMT · By

SMSZombie Trojan Exploits Vulnerability in China Mobile's Payment System

SHARE:

Adjust text size:

Malicious Android app
Enlarge picture
On July 25, TrustGo Security Labs identified a new sophisticated piece of malware that mainly targeted Android users from China. Identified as SMSZombie.A, the Trojan is believed to have infected over 500,000 users.

The malicious element exploits a security hole in the SMS payment system of China Mobile to make unauthorized payments and steal sensitive banking information.

So far, SMSZombie has been identified in seven different apps that have been carefully planted on GFan.com and other Chinese Android application markets.

So, how does the Trojan infect phones?

The malware is spread via shady wallpaper apps entitled something like “Android Animated Screensaver: Animated Album I Found When I Fixed My Female Coworker's Computer.” Once it's installed, it prompts the victim to install additional components which contain its malicious payload.

During this process, it activates a service and makes itself difficult to remove.

After it obtains root privileges, SMSZombie intercepts and forwards incoming SMS messages – which in some cases contain sensitive information – to the attackers.

“By waiting to deliver malicious code until after installation, this virus is difficult to detect. Sophisticated malware like this highlights the fact that the openness of the Android platform is a double-edged sword,” said Xuyang Li, CEO of TrustGo.

“Users are able to access an amazing breadth and variety of apps, but must take precautions to ensure the apps they want have not been compromised by hackers.”

The victims of this threat report that online gaming accounts have been recharged via China Mobile’s SMS payment system.

However, in order to keep a low profile, the malware only steals small amounts of money from the targeted accounts.

TrustGo customers are protected against this threat, but experts advise users to carefully check an application before installing it on their mobile phones.


1,666 hits
Link to this article · Print article · Send to friend

MUST-READ RELATED ARTICLES:


Most Olympics Scams Involved Streaming Sites and Ticket Sales, Experts Found

Russian Android Market Serves “Legitimate” Antivirus Apps That Hide SMS Trojan

F-Secure: 19 New Families of Android Malware Appeared in Q2 2012

Mobile Version of ZeuS Trojan Targets BlackBerry Users

Experts Demonstrate Security Holes in Android with Exploitation Framework

READER COMMENTS:



No user comments yet.
Be the first to express your opinion!
Copyright © 2001-2013 Softpedia. Contact/Tip us at

WindowsGamesDriversMacLinuxScriptsMobileHandheldNews

SUBMIT PROGRAM   |   ADVERTISE   |   GET HELP   |   SEND US FEEDBACK   |   RSS FEEDS   |   UPDATE YOUR SOFTWARE   |   ROMANIAN FORUM