Freebie tricksters unleash spam botnet using Android phones

December 20, 2012 by Nancy Owano report

(—Cloudmark, a San Francisco based messaging security company, posted a notice on Sunday that an Android trojan is being used to create simple havoc, aka an SMS spam botnet. Cyber-thieves dangling the lure of free access to popular games such as Angry Birds Space and Need for Speed Most Wanted are staging attacks for the purpose of turning victims' Android phones into spam-sending monsters. Smartphone security company, Lookout, also based in San Francisco, is referring to the spammer botnet as SpamSoldier. The company also warned that it is spread through SMS messages that advertise free versions of paid games.

Once the user clicks on a link from one of these SMS messages, an application is downloaded that claims to install the game. The user unwittingly activates the SpamSoldier trojan.

This is a mobile created to infect phones so as to spread spam. In this instance, the spam-forwarding trigger is lurking behind the lure of free versions of popular games. The app contacts a web server for a list of phone numbers and can then start sending a flood of text messages. In addition to the game lure, security watchers say infected-phone messages also try to rope in victims by telling them they won a .

Users falling for the scam download apps from a server. They are told to grant the app permission to install and give it the ability to browse the web and send texts. While this should raise suspicions as trouble-bound directives, some users are not phased, said Andrew Conway of Cloudmark: "Not many people read the fine print when installing Android applications."

Once installed, that trojan will begin connections to the command and control server. The "zombie" waits 1.3 seconds after sending each message, and checks with the C&C server every 65 seconds for more numbers. Lookout, meanwhile, has noticed instances of the SpamSoldier on all the major carrier networks in the U.S., and warns that affected users may experience lower speeds along with higher bills. The single infection vector appears to be spam SMS messages. According to Lookout, it has not yet detected SpamSoldier on any major app stores.

Given the large amounts of SMS messages sent, this may not only add up to user costs but also slowdowns, according to Lookout's Derek Halliday. Similarly, Cloudmark's Conway said, "You better have an unlimited message plan or your phone bill may come as a bit of a shock."

The obvious admonishment would be not to download anything from unfamiliar sites. In a Tuesday update, Conway had this additional advice to offer: "So, if you do get SMS spam, don't bother replying STOP to the sender, just forward that message to 7726." The 7726 is SPAM on the keypad and hitting 7726 is designed to stop by reporting it to the phone user's carrier. Cloudmark is continuing to monitor this attack, according to Conway.

Explore further: Android Trojan dubbed ‘Geinimi’ found in legitimate applications

More information:

Related Stories

Microsoft engineer eyeballs Android botnet

July 4, 2012

( -- A Microsoft engineer has spotted a botnet that targets Yahoo! Mail users using Android devices. Terry Zink , who also writes an Internet security blog, said he has evidence of a botnet running on Android devices ...

Text spam messages on the rise

October 12, 2012

Lesley-Ann Thompson's cell phone buzzed the other week with a text message telling her she had won a $1,000 gift card from Best Buy.

Researchers ID 'smishing' vulnerability in Android

November 5, 2012

(—Mobile security researchers have identified a new vulnerability in popular Android platforms, including Gingerbread, Ice Cream Sandwich and Jelly Bean. The vulnerability has been confirmed by Google, and will ...

Recommended for you

Inferring urban travel patterns from cellphone data

August 29, 2016

In making decisions about infrastructure development and resource allocation, city planners rely on models of how people move through their cities, on foot, in cars, and on public transportation. Those models are largely ...

How machine learning can help with voice disorders

August 29, 2016

There's no human instinct more basic than speech, and yet, for many people, talking can be taxing. 1 in 14 working-age Americans suffer from voice disorders that are often associated with abnormal vocal behaviors - some of ...

Sponge creates steam using ambient sunlight

August 22, 2016

How do you boil water? Eschewing the traditional kettle and flame, MIT engineers have invented a bubble-wrapped, sponge-like device that soaks up natural sunlight and heats water to boiling temperatures, generating steam ...


Adjust slider to filter visible comments by rank

Display comments: newest first

not rated yet Dec 20, 2012
Another scam everyone should be aware of is the Amway Tool Scam. Google StopTheAmwayToolScam for more information, and forward this to every non-IBO you know, so they don't get scammed.
not rated yet Dec 20, 2012

"... some users are not phased ..." [sic]
What, ray-gun jammed?

Oh, you mean 'fazed'.
1 / 5 (1) Dec 20, 2012
Another scam everyone should be aware of is the Amway Tool Scam. Google StopTheAmwayToolScam for more information, and forward this to every non-IBO you know, so they don't get scammed.

Amway is just one of the companies out there doing that. At least they do actually sell products too unlike many of the internet business's you can become involved in. Most of those don't actually sell anything but the package info for a person to sell more package info pretending it's information on how to make money on the net. Most of them basically end up being like the old joke of where you see an ad in the paper that tells you how to make money - send your money - get back a piece of paper telling you to put an ad in a paper that says you will tell people how to make money. Many people have made lots of money on that racket and the internet has made it even simpler to do.

Please sign in to add a comment. Registration is free, and takes less than a minute. Read more

Click here to reset your password.
Sign in to get notified via email when new comments are made.