PDA Street

Home | News | Reviews | Features | FREE Downloads | Forums | Compare PDA Prices | Compare SmartPhone Prices


PDAStreet.com > News > Mobile Threat Goes SMiShing For Targets

Mobile Threat Goes SMiShing For Targets

By James Alan Miller
August 29, 2006

McAfee's Avert Labs has identified what it calls a new kind of malware targeting mobile phone users through SMS, where consumers recieve a text messages attempting to get them to click a URL, which in turn dowloads a Trojan horse that allows hackers to control their handset and use it for malicious activities, such as denial of service attacks, installing keylogging software and stealing personal account information.

The antivirus company has dubbed this phenomena, reported by some mobile phone users, as SMiShing (for phishing via SMS). To McAfee, SMiShing is yet another example of how moble devices are becoming increasingly popular vehicles of mayhem and profit to perpetrators of malware, viruses and scams.

With SMiShing, consumers recieve SMS messages along these lines: "We're confirming you've signed up for our dating service. You will be charged $2/day unless you cancel your order at our Web site."

While some folks may recognize this as a scam right away, others might not. The unaware, fearful of incurring premium charges on their bill, click on the link and are prompted to download a program that turns out to be a Trojan.

McAfee warns that although this scamming method may soon become a real annoyance to end-users, it could prove a serious security threat to enterprisess "once hackers learn how to fully exploit SMiShing techniques," according to McAfee mobile threat researcher David Rayhawk, who wrote the Avert Labs blog entry on the subject.

Rayhawk points out, as many have done before, that IT cannot control human behavior, which would be the first line of defense against SMiShing. If an employee avoids clicking on a SMS message URL, then you won't have any SMiShing problems.

He adds, mobile users—the same can be said about many enterprises I think—have yet to learn to treat their mobile devices like laptops. That is, Rayhawk explained to PDAStreet, "The number one issue with smishing attacks - like any phishing attack - is to educate users into treating their smartphones with the same (or better) level of caution as they do with their traditional PCs."

Rayhawk concludes, "Enterprises would be wise to keep a close eye on this issue and think about policies for securing their mobile devices ahead of time, rather than playing catch up when it hits them, and begin to educate their employees about the potential risk now."



Related Links:

  • Mobile Messaging: Part IV - IM Takes on SMS
  • Handheld Security: Part V – Enforce Policies, Keep Network Safe
  • Handheld Security: Part IV – The Mobile VPN
  • Steps to Secure Mobile Workers & Their Gadgets
  • Security: Plug Those Bluetooth Inspired Vulnerabilities

     
     Printable Version
     Email this Story to a Friend  Add Your Opinion



    User Opinions:

    Total: 1 Opinions  -   Displaying: 1 of 1  Read More...


    numbers in your phonebook can be read via gsm
    for over 12months now it has been possible to read a gsm users phonebook remotely via the network

also possible is the ability to send an sms "from" ANY number, ie impersonate your phonebook entries
&#10...more

    Submitted by: dan



     Add Your Opinion  See All 1 Opinions >>



  • PDA/Smartphone Newsletters
    text html text html
    X PDAStreet X Pocket PC Wire
    X iPhoneGuide      

    Other Personal Technology Newsletters
    X Sharky Extreme X WiFi Planet


    internet.commediabistro.comJusttechjobs.comGraphics.com

    Search:

    WebMediaBrands Corporate Info

    Legal Notices, Licensing, Reprints, Permissions, Privacy Policy.
    Advertise | Newsletters | Shopping | E-mail Offers | Freelance Jobs