<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	xmlns:itunes="http://www.itunes.com/dtds/podcast-1.0.dtd"
	xmlns:media="http://search.yahoo.com/mrss/"
>

<channel>
	<title>Fortinet Security Blog &#187; mobile malware</title>
	<atom:link href="http://blog.fortinet.com/tag/mobile-malware/feed/" rel="self" type="application/rss+xml" />
	<link>http://blog.fortinet.com</link>
	<description>Real Time Network Protection</description>
	<lastBuildDate>Wed, 08 Sep 2010 16:35:55 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.8.4</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
		<!-- podcast_generator="podPress/8.8" -->
		<copyright>&#xA9;Fortinet Product Marketing </copyright>
		<managingEditor>jleggio@fortinet.com (Fortinet Product Marketing)</managingEditor>
		<webMaster>jleggio@fortinet.com(Fortinet Product Marketing)</webMaster>
		<category>Fortinet Product Information</category>
		<ttl>1440</ttl>
		<itunes:keywords>forti-gate, anti-spam, anti-virus, fortigate</itunes:keywords>
		<itunes:subtitle>The latest news and information about Fortinet products and services for Real Time Network Protection.</itunes:subtitle>
		<itunes:summary>Fortinet is a leading provider of Unified Threat Management (UTM) network security solutions for enterprise and service provider environments. The Fortinet FortiCast delivers news, information, and tutorials about products, services, and industry trends. Fortinet's FortiGate product line and FortiGuard security subscription services provide an array of integrated network security functions including antivirus, firewall, virtual private networking, intrusion prevention (IPS), web filtering, antispam and traffic optimization. </itunes:summary>
		<itunes:author>Fortinet Product Marketing</itunes:author>
		<itunes:category text="Technology"/>
<itunes:category text="Technology">
  <itunes:category text="Tech News"/>
</itunes:category>
		<itunes:owner>
			<itunes:name>Fortinet Product Marketing</itunes:name>
			<itunes:email>jleggio@fortinet.com</itunes:email>
		</itunes:owner>
		<itunes:block>No</itunes:block>
		<itunes:explicit>no</itunes:explicit>
		<itunes:image href="http://blog.fortinet.com/wp-content/uploads/2009/01/forticast-300x300.jpg" />
		<image>
			<url>http://blog.fortinet.com/wp-content/uploads/2009/01/forticast-144x144.jpg</url>
			<title>Fortinet Security Blog</title>
			<link>http://blog.fortinet.com</link>
			<width>144</width>
			<height>144</height>
		</image>
		<item>
		<title>SymbOS/Album Follows the Path of SymbOS/Yxes</title>
		<link>http://blog.fortinet.com/symbosalbum-follows-the-path-of-symbosyxes/</link>
		<comments>http://blog.fortinet.com/symbosalbum-follows-the-path-of-symbosyxes/#comments</comments>
		<pubDate>Thu, 08 Jul 2010 09:05:01 +0000</pubDate>
		<dc:creator>Axelle</dc:creator>
				<category><![CDATA[Antivirus]]></category>
		<category><![CDATA[Research]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[mobile malware]]></category>
		<category><![CDATA[mobile phones]]></category>
		<category><![CDATA[reverse engineering]]></category>
		<category><![CDATA[sms]]></category>
		<category><![CDATA[symbian]]></category>
		<category><![CDATA[symbos/album]]></category>
		<category><![CDATA[symbos/yxes]]></category>

		<guid isPermaLink="false">http://blog.fortinet.com/?p=1386</guid>
		<description><![CDATA[Lately, I have been analyzing a sample of SymbOS/Album.A!tr, another advanced malware targeting mobile phones running Symbian OS 9 and greater.
First of all, once more, like SymbOS/Yxes, this malware was &#8220;legitimately&#8221; signed by Symbian&#8217;s Express Signed program. The certificate is now revoked:
Serial Number: c8:8e:00:01:00:23:db:45:38:bc:e7:2a:d3:03
Signature Algorithm: sha1WithRSAEncryption
Issuer: C=GB, O=Symbian Limited, CN=Symbian CA I
Validity
    [...]]]></description>
			<content:encoded><![CDATA[<p>Lately, I have been analyzing a sample of <a title="SymbOS/Album.A!tr" href="http://www.fortiguard.com/encyclopedia/virus/symbos_album.a%21tr.html">SymbOS/Album.A!tr</a>, another advanced malware targeting mobile phones running Symbian OS 9 and greater.</p>
<p>First of all, once more, <a title="like SymbOS/Yxes, this malware was &quot;legitimately&quot; signed by Symbian's Express Signed program" href="http://blog.fortinet.com/symbian-certificates-or-how-symbosyxes-got-signed/">like SymbOS/Yxes, this malware was &#8220;legitimately&#8221; signed by Symbian&#8217;s Express Signed program</a>. The certificate is now revoked:</p>
<pre>Serial Number: c8:8e:00:01:00:23:db:45:38:bc:e7:2a:d3:03
Signature Algorithm: sha1WithRSAEncryption
Issuer: C=GB, O=Symbian Limited, CN=Symbian CA I
Validity
    Not Before: Nov 20 05:00:02 2009 GMT
    Not After : Nov 21 05:00:02 2019 GMT
Subject: C=CN, ST=guangdong, L=shenzhen,
O=Shenzhen ZhongXunTianCheng Technology Co.,Ltd.,
OU=PF_V100  1.0.0,
OU=Symbian Signed ContentID,
CN=Shenzhen ZhongXunTianCheng Technology Co.,Ltd.</pre>
<p>Like <a title="SymbOS/Yxes" href="http://www.fortiguard.com/encyclopedia/virus/symbos_yxes.e%21worm.html">SymbOS/Yxes</a>, SymbOS/Album has the capability to silently send SMS messages. It does not do it the same way though: <a title="Yxes uses the RSendAs class" href="http://blog.fortinet.com/how-to-send-an-sms-the-geeky-way/">Yxes uses the RSendAs class</a>, whereas Album uses a non-official Symbian API named <a title="EasyDgm" href="http://developer.symbian.org/wiki/index.php/File:EasyDgmAPI.zip">EasyDgm</a> API (Easy Datagram API). This API sends SMS messages via sockets. Check out the API&#8217;s source code for more details, but basically, this is how it works:</p>
<ol>
<li>open a socket (RSocket) and select the SMS protocol: iSocket.Open(iSocketServer, KSMSAddrFamily, KSockDatagram, KSMSDatagramProtocol);</li>
<li>create a stream to write over that socket: RSmsSocketWriteStream writeStream(iSocket);</li>
<li>dump the SMS message in the stream: writeStream &lt;&lt; *smsMsg;</li>
<li>flush all remaining data in the stream: writeStream.CommitL();</li>
</ol>
<p>SMS messages sent that way are not reported in the phone&#8217;s Sent message box, so they are &#8216;invisible&#8217; to the user (but not to his/her future bill !). To see what&#8217;s happening, one must read the phone&#8217;s internal log file, c:\101f401d\logdbu.dat:</p>
<pre>"28/06/2010","15:26","Short message","Outgoing","Not sent",
   "1*1#","10665xxx"...
"28/06/2010","15:24","Short message","Outgoing","Not sent",
   "@id=200@V1.2.0@YOUR IMSI@3","13410252xxx"...</pre>
<p>The log shows the malware tried to send 2 SMS messages, one to the phone number 10665xxx with text &#8220;1*1#&#8221; and the other one to 13410252xxx with a string containing the IMSI. Those SMS messages had no chance to make it to their recipient because they are only valid in China and I am not ;) (and, of course, I had checked manually in the disassembly what numbers the malware was likely to dial before trying !). Unfortunately, several Chinese users have been less lucky and have reported abnormal bill growth (see Figures 1 and 2).</p>
<table border="0" cellspacing="0" cellpadding="3" width="100%" bordercolor="#000000">
<tbody>
<tr>
<td><a href="http://blog.fortinet.com/wp-content/uploads/2010/07/13410252120-complaint-censored.jpg"><img class="aligncenter size-full wp-image-1391" title="13410252120-complaint-censored" src="http://blog.fortinet.com/wp-content/uploads/2010/07/13410252120-complaint-censored.jpg" alt="13410252120-complaint-censored" width="250" height="116" /></a></td>
<td><a href="http://blog.fortinet.com/wp-content/uploads/2010/07/10665-complaint-censored.jpg"><img class="aligncenter size-full wp-image-1389" title="10665-complaint-censored" src="http://blog.fortinet.com/wp-content/uploads/2010/07/10665-complaint-censored.jpg" alt="10665-complaint-censored" width="250" height="166" /></a></td>
</tr>
<tr>
<td>Figure 1. Chinese user complaining his phone dialed 13410252xxx (text translated from Chinese)</td>
<td>Figure 2. Chinese user complaining about unexpected SMS messages to 10665xxx (text translated from Chinese)</td>
</tr>
</tbody>
</table>
<p style="text-align: left;">The number 10665xxx is special. It corresponds to a service provider number, i.e a special number allocated by the operator to so-called &#8220;service providers&#8221;. In that case, the number was allocated by China Mobile to &#8220;Interactive Technology Co., Ltd. Shenzhen Creation&#8221;.</p>
<p>As for the number 13410252xxx, it corresponds to a personal GSM located in Shenzhen, in the Guangdong Province, and it is operated by China Mobile.</p>
<p style="text-align: center;"><a href="http://blog.fortinet.com/wp-content/uploads/2010/07/13410252-location-censored.jpg"><img class="aligncenter size-full wp-image-1390" title="13410252-location-censored" src="http://blog.fortinet.com/wp-content/uploads/2010/07/13410252-location-censored.jpg" alt="13410252-location-censored" width="369" height="183" /></a></p>
<p>Figure 3. Locating number 13410252xxx (translated from Chinese)</p>
<p>Does that ring a bell? Look at the certificate at the top of this post:</p>
<pre>C=CN, ST=guangdong, L=shenzhen</pre>
<p>Yes, the certificate also belongs to an individual/company located in Shenzhen. No proof, but looks likely both belong to the same person.<br />
Note that the names &#8220;Interactive Technology Co&#8221; or &#8220;ZhongXunTianCheng&#8221; may be fake, or impersonated and hence may not correspond to the malware authors.</p>
<p>Thanks to NetQin for sharing this sample.</p>
<p>&#8211; the Crypto Girl</p>
]]></content:encoded>
			<wfw:commentRss>http://blog.fortinet.com/symbosalbum-follows-the-path-of-symbosyxes/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>10 Predictions for Mobile Malware in 2010</title>
		<link>http://blog.fortinet.com/10-predictions-for-mobile-malware-in-2010/</link>
		<comments>http://blog.fortinet.com/10-predictions-for-mobile-malware-in-2010/#comments</comments>
		<pubDate>Thu, 28 Jan 2010 16:56:45 +0000</pubDate>
		<dc:creator>Axelle</dc:creator>
				<category><![CDATA[Research]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[java/gamesat]]></category>
		<category><![CDATA[mobile malware]]></category>

		<guid isPermaLink="false">http://blog.fortinet.com/?p=917</guid>
		<description><![CDATA[I don&#8217;t know if my recent analysis of Java/GameSat set me on divination, but today I feel like predicting a few things for 2010. And as we&#8217;re already
at the end of January, I should probably hurry.

SymbOS/Yxes will be back and stronger this year. Its authors have probably had time to debug it, and I would [...]]]></description>
			<content:encoded><![CDATA[<p>I don&#8217;t know if my recent analysis of <a id="f0wc" title="Java/GameSat" href="http://www.fortiguard.com/encyclopedia/virus/java_gamesat.a%21tr.html">Java/GameSat</a> set me on divination, but today I feel like predicting a few things for 2010. And as we&#8217;re already<br />
at the end of January, I should probably hurry.</p>
<ol>
<li>SymbOS/Yxes will be back and stronger this year. Its authors have probably had time to debug it, and I would be surprised if they do not release a few versions in the wild.</li>
<li>The AppStore will be abused, unintentionally offering one (or more) malware to the iPhone community. My crystal ball tells me this malware is likely to be a spyware, i.e a malware particularly targeting our privacy.</li>
<li>Hackers will release a Proof of Concept malware for Android.</li>
<li>There will be at least 2 <em>new</em> major malware. I mean <em>really</em> <em>new families</em>, with new implementations, new tricks and extensive press coverage.</li>
<li>People will keep on thinking their mobile phones are not at threat, even though it&#8217;s nothing less than secured.</li>
<li>The amount of spyware, dialers and SMS-sending malware will keep on increasing. Those are areas where malware authors make money.</li>
<li>Social engineering malware such as Koobface will spread to smartphones from which one can blog or tweet on the go.</li>
<li>One of my papers on mobile malware and SymbOS/Yxes will be accepted in a research conference.</li>
<li>Mobile malware will start using cryptography more frequently to conceal their malicious deeds. Apart from encryption of some parts, most of the malware&#8217;s code will remain unobfuscated.</li>
<li>No mobile malware author will be caught, nor sued, sentenced or fined whatsoever.</li>
</ol>
<p>I may turn out to be wrong on a couple of those, but it will be fun looking at this post end of 2010.</p>
]]></content:encoded>
			<wfw:commentRss>http://blog.fortinet.com/10-predictions-for-mobile-malware-in-2010/feed/</wfw:commentRss>
		<slash:comments>4</slash:comments>
		</item>
	</channel>
</rss>
