Malicious programmers focus on smartphones, tablets

May 4, 2011 By Brandon Bailey

Malicious programmers are always looking for new targets. While smartphones and tablets replace PCs as the gadgets we use for messaging, Web surfing and even doing business, some shady characters are starting to target these devices with new forms of viruses, Trojans and spyware.

Researchers at several software companies say that in recent months they've identified a handful of malicious programs hidden in seemingly innocuous applications, including games and video players, that could make Android phones send information and receive commands without the owners' knowledge.

In some cases the purpose was unclear. But one app used a phone's locating software to transmit the owners' whereabouts without permission. Another was designed to quietly send repeated text messages, while charging hefty fees to the owner's wireless account.

The number of threats is tiny compared with the vast array of malware targeting PCs. And at this stage, some experts say it's more important for users to follow common-sense precautions than to purchase one of the commercial antivirus products now offered for mobile devices. But even though the most popular smartphone operating systems may be less vulnerable than PCs, experts say the growing popularity of means malicious coders will inevitably target them more often in the future.

"There hasn't been an example of malware affecting thousands or millions of devices yet, but that doesn't mean it's not possible or it won't happen," said analyst Chris Hazelton, who tracks for the 451 Group, a tech research firm.

"We don't want to be the scaremongers," added Lyle Frink, a spokesman for security software company Avast. "But the development curve for these things is accelerating."

Researchers at another security company, McAfee, say the bulk of the smartphone malware they detected last year was written to target the Symbian used by Nokia, long an international leader in the smartphone industry. But they and other experts have noted an uptick in malicious applications written for Google's Android, which late last year overtook Symbian as the most popular smartphone operating system, according to Canalys, a tech research firm.

"There's a growing installed base of Android users. And it's a very open platform - you can do a lot of good things with it, but if you want, you can also be more nefarious," said Mark Kanok, a spokesman for security software maker Symantec.

Historically, smartphones have used a variety of operating systems. And since a virus written for one platform wouldn't necessarily work on another, the pool of potential targets for any particular virus was small. Also, operating systems and mobile Web browsers have technical features that make it difficult to transfer files or data onto a device without the user's permission.

"They're much more locked down," said Andrew Jaquith, a former mobile industry analyst who is now chief technology officer at Perimeter E-Security.

But as smartphones become ubiquitous, the Android platform has become a prominent target. And experts say another reason they're seeing more Android malware is because Google, seeking to encourage independent developers, makes it relatively easy for anyone to offer an app through the official Android Market.

While Apple is known for closely screening every program offered through its App Store, analysts say Google does virtually no pre-testing or screening of apps in the Android Market. And Android apps can be downloaded from a variety of other sites, which increases the opportunity for bad guys to create a seemingly harmless app that contains malicious code, and then distribute it to an unwitting pool of Android device users.

A Google spokesman declined to comment on the issue of pre-screening apps, but the company said in a statement that it takes security very seriously and has numerous safeguards.

Android's design includes a "sandboxing" feature that prevents individual applications from reading or changing information in other applications or the underlying operating system, without first getting permission. That's why users who download an Android app typically get a message asking permission to access other services or software on the device.

Experts say smartphone users should not agree to anything that seems suspicious, although less savvy users may not understand what they're allowing.

The Android Market also displays user ratings and reviews, and Google encourages users to consider those before downloading any app. When the company has learned of a problem, it has yanked apps from the Android Market. And twice in the last year, Google has used its ability to remotely remove certain apps from any device that had downloaded them, under the "terms of service" that Market users agree to accept.

In the most recent incident, Google disclosed last month that it had remotely killed several malicious apps that were transmitting information about the host device and its location. The company also used its ability to automatically install a security update on the affected devices to prevent further unauthorized transmissions.

"We are adding a number of measures" that would prevent similar apps from being distributed in the future, the company said in a blog post.

While crediting Google with reacting quickly, Hazelton noted that Google only learned of the malware from an independent developer after it had been downloaded an estimated 250,000 times. And as more users download more kinds of apps from a variety of sources, he said there's an increasing risk of malware getting past the security safeguards.

"We're seeing these things come almost in development cycles, where people are putting out different versions, testing their capabilities and incorporating new methodologies," added Symantec's Kanok.

Symantec, McAfee and several other software companies sell products that combine mobile antivirus software with features that allow consumers to back up their data, locate a missing phone and lock or "wipe" personal data if the device gets lost or stolen. Experts say these can be useful, but several said the most important thing owners can do is lock their device with a password.

While not every smartphone user currently needs antivirus software, Hazelton said the need likely will increase as banks and financial institutions offer more apps and online services for mobile devices.

"It comes down to each user and what they do with that device," he added.

(c) 2011, San Jose Mercury News (San Jose, Calif.).
Distributed by McClatchy-Tribune Information Services.


Rank not rated yet
Relevant PhysicsForums posts

More news stories

Browser wars flare in mobile space

The browser wars are heating up again, but this time the fight is for dominance of the mobile Internet.

Technology / Software

created 2 minutes ago | popularity not rated yet | comments 0

SpotterRF debuts Radar Backpack Kit (w/ Video)

(Phys.org) -- SpotterRF has announced a special radar backpack kit designed to enhance situational awareness for soldiers on the ground. The company says its special radar is designed for warfighters as part ...

Technology / Hi Tech & Innovation

created 21 hours ago | popularity 5 / 5 (5) | comments 12 | with audio podcast report

Probability of contamination from severe nuclear reactor accidents is higher than expected: study

Catastrophic nuclear accidents such as the core meltdowns in Chernobyl and Fukushima are more likely to happen than previously assumed. Based on the operating hours of all civil nuclear reactors and the number ...

Technology / Energy & Green Tech

created May 22, 2012 | popularity 3.6 / 5 (21) | comments 56 | with audio podcast

Delphi gasoline-injection engine technique rivals hybrid's edge

(Phys.org) -- Running a diesel like engine on gasoline is something Delphi is doing in notable fashion. They claim they are on to a promising way to enjoy an engine that gives the vehicle owner high efficiency ...

Technology / Energy & Green Tech

created May 21, 2012 | popularity 4.7 / 5 (18) | comments 38 | with audio podcast report

HyperSolar shows dirty water no barrier to power world

(Phys.org) -- The Santa Barbara, California, company, HyperSolar, is set to transparently share the ups and downs of its research experiences toward the company’s ultimate vision, successfully producing ...

Technology / Energy & Green Tech

created May 24, 2012 | popularity 4.8 / 5 (15) | comments 17 | with audio podcast report


Scientist: Evolution debate will soon be history

(AP) -- Richard Leakey predicts skepticism over evolution will soon be history. Not that the avowed atheist has any doubts himself.

Dell tablet leak: 10.1-inch display, two-battery choice

(Phys.org) -- Headline after headline talks about vendors’ tablets in the wings as likely number-one contenders for the iPad. Such claims have justifiably been taken with a grain of salt, considering ...

SpaceX capsule has 'new car' smell, astronauts say (Update)

SpaceX's Dragon cargo vessel smells like a new car, said astronauts at the International Space Station after opening the hatches Saturday following the spacecraft's landmark mission to the orbiting lab.

Thousands of shellfish found dead in Peru

Thousands of crustaceans were found dead off the coast of Lima following the mystery mass death of dolphins and pelicans, the Peruvian Navy said Friday.

Australia hails surprise super-telescope decision

Australia has hailed a surprise decision giving it a role in a radio telescope project aimed at revolutionising astronomy, vowing to draw on its decades of experience in space science.

Astronomers seize last chance in lifetime for Venus Transit

Astronomers are gearing for one the rarest events in the Solar System: an alignment of Earth, Venus and the Sun that will not be seen for another 105 years.