Ramblings of an old Doc
The future is sooner than we think!
Published on January 2, 2011 By DrJBHL In Personal Computing

 

So why is Doc telling us about a Trojan-Virus for a phone so few have?

The reason is that Sydneysiders PM'd me with this story and by doing so in her usual, understated Ozzie way, dropped a bomb with a sputtering fuse right in my lap(top). 

 

The implications are quite unpleasant for us all.

 

First some background.

A virus infecting mobile phones using Google's Android operating system has emerged in China that can allow a hacker to gain access to personal data, US security experts said in reports on several websites.

 

 

A report this week from Lookout Mobile Security said the new Trojan affecting Android devices has been dubbed "Geinimi" and "can compromise a significant amount of personal data on a user’s phone and send it to remote servers."

The firm called the virus "the most sophisticated Android malware we've seen to date."

"Once the malware is installed on a user's phone, it has the potential to receive commands from a remote server that allow the owner of that server to control the phone," Lookout said.

According to Lookout:

The specific information it collects includes location coordinates and unique identifiers for the device (IMEI) and SIM card (IMSI). At five-minute intervals, Geinimi attempts to connect to a remote server using one of ten embedded domain names. A subset of the domain names includes www.widifu.com, www.udaore.com, www.frijd.com, www.islpast.com and www.piajesj.com. If it connects, Geinimi transmits collected device information to the remote server.

"Geinimi's author(s) have raised the sophistication bar significantly over and above previously observed Android malware by employing techniques to obfuscate its activities."

The motive for the virus was not clear, accodring the Lookout, which added that this could be used for anything from "a malicious ad-network to an attempt to create an Android botnet." It could be used to install other, more harmful malware on your Android Phone.

Looks like we may be seeing a shift from virus attacks on computers to attacks on phones.

It bothers me that there also has been a recent contretemps between Google and the Chinese Government in which I have read that there was a planned and executed cyber attack on Google by the government of the PRC. Could this be additional “punishment” of Google for not knuckling under to Chinese demands or perhaps an attack by those incited by the dispute?

Lookout said the only users likely to be affected are those downloading Android apps from China. I’m not so sure.

The infected apps included repackaged versions sold in China of:

  • Monkey Jump 2
  • Sex Positions
  • President vs. Aliens
  • City Defense
  • Baseball Superstars 2010

"It is important to remember that even though there are instances of the games repackaged with the Trojan, the original versions available in the official Google Android Market have not been affected," the security firm said.

This doesn't appear to be a giant threat. In order to get infected, you would have to either install a sideload app from a 3rd party or Chinese Market, meaning the trojan doesn’t come to your phone by way of the official Android Market or buy an infected phone on eBay (for example – it is unclear whether such phones have reached eBay yet).

 

 

So, “be careful out there”, users and always make sure your apps are coming from a legal, legit source. Lookout Mobile Security, however, has been updated to protect against the malware, so be sure to get it here if you aren’t already using it.

"OK, Doc… we’ve put up with your long winded stuff…what’s your point?”

One: Be alert as to what apps you put on your phone. Windows and iPhone attacks are coming.  It’s just a matter of time.

Two: Trojans and viruses have entered a new arena: "Put on some armor!”

http://www.appbrain.com/app/lookout-mobile-security/com.lookout

Three: Learn a lesson from the Swine Flu and Avian Flu (remember? They started in pigs and birds and jumped to people). In the cyber future (not so distant), the stuff that gets on your phone will migrate to your computer, yes, even across OS’s.


Comments
on Jan 02, 2011

Bump

on Jan 03, 2011

While this bug is disconcerting (I was looking at getting a Droid this year), the concept is not new - I think it was back in 07 that one of the PC Sites was talking about bugs for phones being the new rage (I am just glad that they have not taken off until now).

But it now brings up the issue of AV for the smart phones.  I hope we get an AVG type of product as I really hate the bloatware that has become the industry leaders on the PC.

on Jan 03, 2011

But it now brings up the issue of AV for the smart phones. I hope we get an AVG type of product as I really hate the bloatware that has become the industry leaders on the PC.

https://www.mylookout.com/download  Free for you. There's a premium one as well.

on Jan 03, 2011

Thanks!  I will bookmark the site for when I get mine (probably late spring)!

on Jan 03, 2011