Russia home to text message fraud "cottage industry"

August 2, 2013
Researchers have discovered that bilking people by infecting Android mobile phones with viruses has become a cottage industry in Russia in a criminal model that could be replicated elsewhere. While the text-messaging malware industry appeared centered in Russia, the model could be duplicated in other countries where conditions allow, according to Lookout Mobile Security.

Researchers have discovered that bilking people by infecting Android mobile phones with viruses has become a cottage industry in Russia in a criminal model that could be replicated elsewhere.

Members of Lookout Mobile Security were at the infamous Def Con hacker gathering in Las Vegas on Friday to share what they uncovered about a text-messaging fraud operation they dubbed "Dragon Lady" in reference to Cold War-era US military reconnaissance aircrafts.

"The mobile malware trade in Russia is highly organized and profitable," Lookout said, referring to designed to infect smartphones.

"We recently investigated a veritable industry of malware businesses with startup-like behaviors."

Businesses referred to as 'Malware HQs' accounted for more than half the overall mobile malware detections by Lookout during the first six months of this year, according to researcher Ryan Smith.

Malware HQs openly recruit 'affiliates' that could be anyone and provide simple do-it-yourself tools to distribute viruses with tactics such as booby-trapped websites or Twitter posts.

Once on smartphones, fire off premium text messages behind the scenes, with HQs getting the money and sharing it with affiliates who hooked the victims.

Lookout discovered that some HQs promote playful competition between affiliates with websites that show rankings and promise prizes for top performers.

"We've seen evidence that these affiliate marketers have earned between $700 a month to $12,000 a month from these scams," Smith said in a report summarizing Lookout's findings.

He estimated that there are thousands of individual distributors and potentially tens of thousands of affiliate websites promoting custom SMS malware.

"Malware HQs handle the tough stuff like releasing new Android code and configurations every two weeks, malware hosting, shortcode registration, and marketing campaign management tools," Smith said in his summary.

"Like any other large business, Malware HQ organizations provide customer support, post regular newsletters, report downtime or new features, and even run regular contests to keep their affiliates engaged and motivated."

Those falling prey to the were typically Russian speaking Android phone users searching online for free games, applications, music, videos or pornography, according to Lookout.

Pages rigged with malware are designed to reject visits from countries not targeted by the crooks, who prefer victims in places where fees for premium text messages are paid immediately instead of through billing by telecom service providers.

While the text-messaging malware industry appeared centered in Russia, the model could be duplicated in other countries where conditions allow, according to Lookout. gc/rcw

Explore further: Security firms see rise in smartphone cyber-attacks

Related Stories

Staggering surge in Android gadget viruses: Juniper

November 16, 2011

The arsenal of malicious code aimed at Android-powered gadgets has grown exponentially, with criminals hiding viruses in applications people download to devices, according to Juniper Networks.

'Phishing' scams explode worldwide, researchers shows

June 21, 2013

Those insidious email scams known as phishing, in which a hacker uses a disguised address to get an Internet user to install malware, rose 87 percent worldwide in the past year, a security firm said Friday.

Recommended for you

Your (social media) votes matter

January 24, 2017

When Tim Weninger conducted two large-scale experiments on Reddit - otherwise known as "the front page of the internet" - back in 2014, the goal was to better understand the ripple effects of malicious voting behavior and ...

Protective wear inspired by fish scales

January 24, 2017

They started with striped bass. Over a two-year period the researchers went through about 50 bass, puncturing or fracturing hundreds of fish scales under the microscope, to try to understand their properties and mechanics ...

'Droneboarding' takes off in Latvia

January 22, 2017

Skirted on all sides by snow-clad pine forests, Latvia's remote Lake Ninieris would be the perfect picture of winter tranquility—were it not for the huge drone buzzing like a swarm of angry bees as it zooms above the solid ...

Singapore 2G switchoff highlights digital divide

January 22, 2017

When Singapore pulls the plug on its 2G mobile phone network this year, thousands of people could be stuck without a signal—digital have-nots left behind by the relentless march of technology.

Making AI systems that see the world as humans do

January 19, 2017

A Northwestern University team developed a new computational model that performs at human levels on a standard intelligence test. This work is an important step toward making artificial intelligence systems that see and understand ...

0 comments

Please sign in to add a comment. Registration is free, and takes less than a minute. Read more

Click here to reset your password.
Sign in to get notified via email when new comments are made.