Channel News and Analysis - Channel Insider
Empowering the next generation Channel
 
Bull’s Eye Awards
Nominations Open for Channel Insider 2009 Bull’s Eye Awards
Nominations are now open for the Channel Insider 2009 Bull’s Eye Awards, which recognize excellence in customer service, technology prowess, business acumen, channel leadership, communications and community building, and innovation among vendors, solution providers, distributors and channel services companies.



Sponsored Links
  • SonicWALL breaks through network and email gridlock
  • Save up to 40% on calling costs with Avaya Aura™
  • HP PartnerONE | SolutionsINFINITE Visit us at hp.com/partners/us/go/4



  •  

    First J2ME Mobile Phone Trojan Spotted

    in Channel News and Analysis


    Article Rating:starstarstarstarstar / 0
    Article Views: 916

    Rate This Article:
    Add This Article To:
    Russian anti-virus specialist Kaspersky Lab has discovered evidence of the first mobile phone Trojan written for low-end J2ME cell phones.

    Russian anti-virus specialist Kaspersky Lab has discovered evidence of the first mobile phone Trojan targeting J2ME (Java 2 Platform, Micro Edition) devices.

    The sample Trojan, identified as Redbrowser.A, works on most phones with J2ME support, raising fears that malware writers are expanding the target beyond just Symbian-based smart phones.

    Redbrowser.A is a J2ME-based Java Midlet that pretends to be a WAP (Wireless Application Protocol) browser that offers free WAP browsing.

    Instead, once a phone is infected, the Trojan sends text messages to premium rate numbers, saddling the victim with exorbitant messaging charges.

    The infected user gets charged between $5 and $6 for each text message sent by the Trojan, said Shane Coursen, Kaspersky Lab's senior technical consultant.

    Resource Library:

    In an interview with eWEEK, Coursen said the Trojan, which was not found in the wild, is further proof that the mobile malware threat "is expanding rapidly."

    Click here to read more about cell phone viruses.

    "We now know that it's not only a threat to smart phones. All these regular phones that support J2ME are vulnerable and can become a major target," Coursen added.

    The Redbrowser.A Trojan can be downloaded to the victim handset either via the Internet (from a WAP site) or via Bluetooth or a personal computer, he said.

    F-Secure, a Finnish anti-virus vendor, has issued updated virus definitions for the latest threat.

    "The fact that Redbrowser claims to send free SMS messages as part of its normal operation, is to fool the user into allowing the application permission to use Java SMS capabilities in phones that require permission from the user before sending SMS messages. This claim of free service is a form of social engineering," said F-Secure researcher Jarno Niemela.

    He said the social engineering texts are in Russian, which limits the Trojan only to Russian-speaking countries.

    Read more here about the Cabir worm targeting smart phones.

    Niemela said the Trojan contains a fixed list of 10 phone numbers to which it will send SMS messages.

    After the social engineering texts are shown, Redbrowser.A it will pick one number from the list at random and send a SMS message to that number.

    "The message sending function is in an infinite loop, so unless terminated by the user, it will send a constant stream of messages. Each of those message will be changed to the user's account," Niemela said.

    A separate blog entry by F-Secure's Mikko Hypponen contains screenshots of Redbrowser infecting a Nokia 6630 cell phone.

    "Some old Java viruses like Strangebrew do work on some Java phones, but RedBrowser is the first malware targeting Java phones on purpose," Hypponen said, noting that it is also the first mobile malware that tries to steal money.

    "The threat is still very limited; this thing does not spread by itself, and we have no direct reports of anybody being hit by it in Russia [where the first reports were from]," he added.

    Hypponen said the Redbrowser Trojan works on many low-end closed phones.

    F-Secure has successfully tested it under Nokia 9300 (Communicator, running Symbian Series 80), Nokia 6630 (Symbian S60 smart phone), Nokia 5140i (low-end Series 40 phone).

    "We've also heard it works under BlackBerrys with J2ME support. We will be testing it with Nokia 6310i—one of the first phones with Java support," he said.

    Check out eWEEK.com's for the latest security news, reviews and analysis. And for insights on security coverage around the Web, take a look at eWEEK.com Security Center Editor Larry Seltzer's Weblog.



    Discuss First J2ME Mobile Phone Trojan Spotted
     
    >>> Be the FIRST to comment on this article!
     

     
     
    >>> More Channel News and Analysis Articles          >>> More By Ryan Naraine
     


     


    [ci] feeds
    XML
    Add Channel News, Product Reviews, Trends and Analysis to your RSS newsreader or My Yahoo!


    HTML PLAIN TEXT

    Keep on top of news for VARs and Resellers with CI's Weekly Newsletter and Alerts.

     


    CHANNEL RESOURCE CENTER
     
     
    How to Unleash Application Performance with Solid-State Drives and Sun Servers
    Unleash the Beast! Learn from Sun and Intel experts how Sun servers equipped with Flash-enabled solid-state drives offer dramatic improvements to HPC, Web 2.0, and data center application performance Watch this video to learn more
    Watch Video
     
    Build A More Efficient Data Center
    Demands are growing but budgets are not. Solve your pressing IT issues using the resources you already have. Determine which technologies can help you drive efficiencies and how they are applied. Gain a quick ROI on new initiatives
    Find out how
    Easily Monitor Virtual, Physical, and Cloud based assets, applications and services from a unified Dashboard with up.time. Deep Monitoring across platforms and best-of-breed reporting. Over 700 enterprise customers in 32 countries.
    Read Article