Beware Of Android SMS Worms

Google's Android now dominates 80% of the smart phone market. Of the major phone operating systems, Android is the most vulnerable to security breaches and yet perceptions haven't caught up with reality. People simply aren't as worried, or as careful, as they ought to be.

Worms picture from Shutterstock

If you're using an Android and aren't too concerned, maybe a recent announcement by a leading anti-malware company will make you stop and think. When were you last suspicious of a text from a friend?

Well, now is the time to start checking your messages with more scepticism as a virus known as "Andr/SlfMite-A" has been spreading throughout the Android world, transmitted by text messages, also known as SMS.

If you are fooled into clicking on a link embedded within the SMS, and if your phone is unprotected, the virus will in turn be installed on your own phone. The virus will then attempt to send text messages to your first 20 contacts. The message may look something like this:

By making your contacts think this message is from you and is therefore a genuine (and seemingly honest) text message which they must act upon. It tricks them into clicking the link, unleashing malware onto their phone. And so on.

If this all sounds familiar, it is because self-replicating "worms" like these were a feature of early mass-market online viruses. A decade ago, famed worms such as ILOVEYOU or Mydoom spread through email, shutting down computer systems throughout the world and causing millions of pounds in damage.

Today's SMS spam is spread in the same way, but things move even faster now. As soon as anyone clicks on the link, they become part of the worm's progress. You may only be one victim with 20 contacts, but these things soon add up. If all 20 contacts fell for the link once every hour, the worm could have swamped the entire planet and all its Android devices within a day.

Fortunately not everyone falls for this, nor do all the text messages get through. In the end, Andr/SlfMite-A is likely to fizzle out. However, whether it is successful in infecting your friends, the virus also downloads a small malware application which appears to direct users towards Mobogenie, an independent Android app store.

It is important to note that Mobogenie has been hit in the past by other malware issues. There's a reason the anti-malware community don't consider it an effective resource for protecting your smart phone.

Should I panic?

If you already have an anti-malware application installed on your android smart phone, just check to see that its malware definitions are up to date. Then rest easy and make yourself a nice refreshing drink.

But if you do not have any protection I would be very concerned and strongly advise that you consider installing an antivirus app.

If you do get a mysterious text message from one of your contacts my best advice is to phone them and ask if they intended to send a message. If it looks as if they may be infected, point them to this article and advise them to ensure that their phone is protected.

Android is a victim of its success

Any computer and any operating system is potentially vulnerable to malicious code. So long as unsuspecting souls can be persuaded to download applications for their own personal benefit, cybercriminals will be able to exploit systems and create all kinds of mayhem.

Sadly, research has shown that over half of us could be persuaded to download malware for the right price. In some cases, manufacturers have managed to stem the supply: Apple and Microsoft, for instance, retain tight control over their smart phone app stores, ensuring a high degree of safety.

But the reality is that cybercriminals tend to target popular systems, and Android is increasingly dominant. There are many naive people out there, and more than one way to install dodgy apps.

It is important that everyone using any technology becomes more aware of the different types of attacks out there as you cannot entirely rely on experts to protect your smart phone from every attack.

We don't all use our phones in the same way so nor are we all exposed to the same degree of risk. The way you respond to texts, emails or browser messages, the sites you visit and the applications you may download all have an effect on the security of your smart phone.

Becoming cautious should be a way of life. There is nothing wrong with checking to see if an unusual text message from a friend is suspicious; who knows, maybe they'll even appreciate hearing your voice.The Conversation

Andrew Smith is Lecturer in Networking at The Open University. He does not work for, consult to, own shares in or receive funding from any company or organisation that would benefit from this article, and has no relevant affiliations.

This article was originally published on The Conversation. Read the original article.


Comments

    Some details on this would be nice. Does it effect the newest versions of the operating system with the real time monitoring of apps?

    How does it install? Do I need to have sideloading turned on for it to work etc?

      So far as I can tell, it installs when someone follows the link in the message and opens the file when it finishes downloading (unless they are using a browser which can be tricked to auto-run it) and has sideloading enabled (and presumably clicks the 'install' button when the file downloads and pops up to install). On versions of Android with recent services installed the file should also be checked by the Google verify feature.

      I'd quite like to get my hands on the APK, because I'm curious and want to disassemble it. However, I can't find it anywhere, and if my list of steps above is correct then I'm pretty sure no-one I know will get infected with it either.

        So it's only a worry if people are stupid and install stuff from an SMS.

        Pity so many people are stupid.

          That's the impression I get. Hopefully the Google verification will block it for even stupid people.

    @AndrewSmith this is a very misleading and incorrect article.

    In order for someone to fall into this trap you need to enable developer mode, enable third party sources and still be stupid enough to install software from somewhere other than the Google Play Store from what could only be described as obvious spam.

    Adrian Ludwig, the lead engineer for Android security at Google has recently make very clear statements about absolute Malware counts on Google Android - "It's a convenient way for [security firms] to [count] it like that because it never goes down. If you just count that number the world always looks worse, which [is what] sells their product,"

    In addition open source programs manager at Google Chris DiBona stated anti-virus firms were playing on consumers' fears "to try to sell you bulls**t protection software" and claimed that the supposed mobile malware problem was a bogus scare campaign created by the security companies. "If you work for a company selling virus protection for Android, RIM or iOS, you should be ashamed of yourself,"

    In fact the number of infections on non-modified Android phones and tablets is no higher than that of Apple iOS and significantly less than Windows or Mac OSX.

    So Andrew, I suggest you put some more effort into research before you put pen to paper. Maybe a retraction or correction about the security of the Android operating system is in order.

    BTW: are you an iPhone user? [Insert conflict of interest here]

    Who texts a friend starting with "Dear (Name)"? That'd set off alarm bells for me...

Join the discussion!