Latest news
Despite Android’s dominance in the mobile threat landscape, the Symbian malware scene is far from dead. 21 new families and variants were discovered in the third quarter of 2012, a 17% increase compared to the second quarter.
A typical Symbian malware is a trojan that mimics a system update or a legitimate application. The object-capability model used in Symbian devices presents some loopholes that can be exploited. For example, the same set of capabilities required by a legitimate action game may be similar to that required by an application that can download and install new software from the Internet. A malware author can capitalize on these similar capabilities to present a malware as a harmless, coveted program that sneakily carries out its activities without arousing the user’s suspicion.

Most of the Symbian malware originates in China and are distributed for the purpose of making a profit. Most of these (for example, Fakepatch.A and Foliur.A) are involved in SMS-sending activities. The SMS messages are usually sent to premium rate numbers or those associated with SMS-based services. Malware authors and distributers can easily turn an infection into profit by taking advantage of a ‘built-in’ billing mechanism for these SMS services; the malware simply sends out SMS messages that silently sign up the device owner for a premium subscription service, incurring charges the user’s account.
Another profit-generating method involve the malware emulating a user’s behaviour and enabling WAP services on the device, which are then billed through the mobile service operator. These malware, such as PlugGamer.A, are capable of acting as scripted bots, silently playing a regular, albeit simple browser-based online game over the WAP service.
Despite the continuing activity on the Symbian malware scene, the Symbian platform itself saw a significant blow to its future, as Nokia confirmed in September that the once popular operating system has now been put in “maintenance mode”, with the only major update this year being a refresh or feature pack that was rolled out in August to certain devices running the current Nokia (formerly Symbian) Belle release.
Market-wise, shipment of Symbian smartphones reportedly fell by 62.9% in Q2 and Symbian now accounts for only 4.4% of the global smartphone market. Despite the lack of activity in platform development and use however, Symbian malware is still likely to be active for some time to come as many users, particularly in developing countries, continue to use existing Symbian-based handsets.
Source: F-Secure Mobile Threat Report Q3 2012.


Spotlight

The security of WordPress plugins
Posted on 18 June 2013. | Checkmarx’s research lab identified that more than 20% of the 50 most popular WordPress plugins are vulnerable to common Web attacks, such as SQL Injection.

Information security executives need to be strategic thinkers
Posted on 17 June 2013. | George Baker, the Director of Information Security at Exostar, talks about the challenges in working in a dynamic threat landscape, offers tips for aspiring infosec leaders, and more.

Large orgs in denial about own security breaches?
Posted on 14 June 2013. | Over two thirds (66%) of large organizations said they either had not experienced a security incident in the last 12-18 months or were unsure if they had.

Vulnerability scanning with PureCloud
Posted on 12 June 2013. | nCircle PureCloud is a cloud-based network security scanning product built upon the companies' vulnerability and risk management system IP360.

Reactions from the security community to the NSA spying scandal
Posted on 11 June 2013. | Read on for comments on this scandal that Help Net Security received from a variety of security professionals and analysts.
By subscribing to our early morning news update, you will receive a daily digest of the latest security news published on Help Net Security.
With over 500 issues so far, reading our newsletter every Monday morning will keep you up-to-date with security risks out there.







