Monday, February 23, 2009

A new SMS mobile worm!

This new worm, deemed SymbOS/Yxes.A!worm (also known as 'Sexy View', is targeting mobile devices running SymbianOS S60 3rd Edition (eg: Nokia 3250), but may run on a wider range of devices, as it has been reported to function on phones operating SymbianOS S60 3rd edition FP 1 (eg: Nokia N73).

It bears a valid certificate signed by Symbian, and installs as a valid application on factory mobile devices running S60 3rd Edition. The Yxes mobile worm is reported to be currently spreading in the wild.

The worm gathers phone numbers from the infected device's file system, and repeatedly attempts to send SMS messages to those. The messages feature a malicious Web address (URL); upon 'clicking' on the address in the received message, the recipients will download a copy of the worm (provided their phones/subscriptions allow for internet browsing).

Beyond propagating to as many users as possible via the strategy mentioned above, the worm's aim is to gather intelligence on the infected victim (such as serial number of the phone, subscription number) and post it to a remote server likely controlled by cyber criminals. Whatever the latter may do with such information is unknown as of writing.

No comments:

Post a Comment