By IDG Enterprise

New Android malware disguised as security app

November 05, 2012 11:58 AM via CSO

Google's Android mobile platform is the target of a new variant of a widely used malware capable of stealing personal information.

The latest Zeus malware masquerades as a premium security app to lure people into downloading the Trojan, Kaspersky Lab reported Monday. The fake security app, called the Android Security Suite Premium, first appeared in early June with newer versions released since then.

Such malware presents a threat to consumers, as well as businesses that allow employees to use their personal devices on the corporate network. A Dimensional Research survey of IT professionals found that more than 70 percent said mobile devices contributed to increased security risks and that Android introduced the greatest risk. Issued in January, the report was sponsored by firewall vendor Check Point Software Technologies.

The Huge BYOD Risk You're Probably Ignoring
Stay on top of CITE: Subscribe to the InCITE newsletter.

The new Zeus malware steals incoming text messages and sends them to command-and-control servers operated by the attackers. Depending on the apps installed on the Android device, the text could include sensitive data, such as password-reset links.

"It is also important to mention that these malicious apps are able to receive commands for uninstalling themselves, stealing system information and enabling/disabling the malicious applications," Denis Maslennikov, a Kaspersky security researcher said in a blog post.

The malware installs a blue shield icon on the smartphone or tablet menu and shows a fake activation code when executed, Kaspersky said. The app uses a series of six command and control servers, one of which was linked to Zeus malware found in 2011.

"The newest variant of ZitMo demonstrates the commitment to effective mobile spyware development and distribution that cybercrime has made," Kurt Baumgartner, senior security researcher at Kaspersky Lab, said by email.

Android application infections increased dramatically in the first quarter of this year, driven by a surge in attacks on personal data, according to the E-Threat Landscape Report released in April by security vendor Bitdefender. Cyber-criminals often hide the malware in apps sold in online stores.

The Dimensional survey found that 65% of the 768 IT pros polled allowed personal devices to connect to corporate networks. Apple's iOS, used in the iPhone and iPad, was the most common platform, with Android coming in third behind Research in Motion's BlackBerry. Android was found in companies represented by one in five of the respondents.

A factor that increases the risk of malware such as Zeus is the lack of employee awareness. More than six in 10 of the IT pros surveyed said employee ignorance had the greatest impact on mobile security.

The types of corporate information most often found on mobile devices were e-mail and contacts. Other information cited by the respondents included customer data, network login credentials and data made available through business applications.

Zeus was first discovered in 2007 as a keystroke logger and form grabber that ran in a browser. The malware is primarily downloaded through phishing schemes or by visiting malicious Web sites. The mobile version of Zeus, called ZitMo, was first discovered a couple of years ago.

Originally published on www.csoonline.com. Click here to read the original story.
Reprinted with permission from csoonline.com. Story copyright 2012 csoonline.com communications. All rights reserved.
Latest Stories
June 18, 2013 3:48 PM

You don't need Office for iPhone - here are 15 great alternatives

iStockPhoto

Here's a full rundown of options for working with Office files on your iPhone.

June 18, 2013 3:08 PM

5 easy ways to make Android devices more secure

Here are some basic steps anyone can take -- including enterprise workers -- to improve security on their personal Android BYOD devices.

June 18, 2013 1:28 PM

HP replaces the chief of its PC business

HP

A new role for Todd Bradley, who's overseen HP's PC and printer business for the last couple years.

June 18, 2013 12:39 PM

How SAP hopes to win from the Internet of Things

SAP TV

SAP is making a big bet on machine-to-machine communications, but admits there are still a few hurdles to overcome before it turns into reality.

June 17, 2013 3:41 PM

Apple is really pushing the iPhone 4 in China, and it's paying off

Sales were up more than 3x from the previous quarter.

June 17, 2013 1:24 PM

Apple and Microsoft fight it out for iPhone users

Apple is playing defense with iWork for iCloud, while Microsoft is going on offense with Office Mobile. The prize? Tens of millions of iPhone users.

FOLLOW US
Get CITEworld updates via email, RSS or social media