Showing posts with label mobile spyware. Show all posts
Showing posts with label mobile spyware. Show all posts

Tuesday, September 30, 2014

Mobile Spyware: Finally criminal?

Commercial Mobile Spyware apps have been around for over a decade. They've been on every platform with the best(if one can call it that) support on the most popular Operating Systems. They're usually sold as tools to help one monitor their children or keep track of a spouse or significant other. Tracking the latter groups lean toward a gray or even a black/illegal area.

The FBI has come along to the idea that folks selling spyware(or at least mobile spyware) are committing a crime. Specifically since your phone is a telecommunications device, installing spyware on it is the same as wiretapping.  Also the CEO of Invocode(producers of StealthGenie spyware) and his employees are members of a "criminal conspiracy responsible for StealthGenie".  Fortunately, the FBI arrested the CEO in Los Angeles over the weekend.

StealthGenie is a spyware app that supports iOS, Android and Blackberry OS. Blackberry support only applies to pre Blackberry 10 devices so newer devices would not be vulnerable. The capabilities of the spyware is not breaking any new ground, we've seen all of this before and in software from their competitors.

StealthGenie's hompage - The World's Most Powerful Mobile Phone Spy Software"

Intriguingly from the Government's complaint, Invocode expected that the majority of their sales of the StealthGenie mobile spyware would be to "[s]pousal cheat: Husband/Wife of boyfriend/girlfriend suspecting their other half of cheating or any other suspicious behaviour or if they just want to monitor them.".  So mainly to monitor someone else's phone without their permission.  The FBI agents purchased a copy of StealthGenie and were able to immediately monitor the calls and text messages from another of their phones.  While investigating monitoring software from competitors of Invocode, I've also seen that they perform similarly or perform additional functions.

Speaking of Invocode's competitors, they don't seem to think highly of StealthGenie:

"...simply isn't worth the money!" - advice from other criminals?

This screenshot above is from a competitor that recommends two other mobile spyware packages in addition to itself that they prefer to StealthGenie. This implies that these are three other, possibly more powerful, mobile spyware and "wiretapping"/interception tools that are still available on the app markets. I applaud the US government going after Invocode in the "first-ever criminal case concerning the advertisement and sale of a mobile device spyware app".

Due to the gray-area uses of mobile spyware, Anti-malware and Anti-Spyware companies have had to come up with classifications to keep us from stepping on possibly legal  developers of spyware. This is mainly to avoid being sued for being anti-competitive or harming the business of legitimate monitoring software developers. It would certainly ease matters now that governments are starting to criminally prosecute producers of tools that can be used to intercept users calls and texts.

--------------

If you're curious about the legality of selling mobile spyware, the US Government cites the following sections of law:

Title 18, United States Code,
Section 2512(l)(b) (sale of an interception device)
Section 2512(l)(c)(i) (advertisement of a known interception device)
Section 2512(l)(c)(ii) (advertising a device as an interception device)

One can read the details themselves in the Federal complaint.

Thursday, August 14, 2014

On the Mobile Malware Lifecycle

A number of factors drive malware on new platforms. The chance for pure discovery and experimentation, the desire to be the first, a need to make an income. Truthfully these are the same reasons that drive legitimate software development. This is no surprise as malware development is a form of software development.

The accelerated pace of new platforms entering the market also accounts for a rise in malware. This also leads to a shorter lifecycle for malware and malware development. The current lifecycle, bolstered by more means of revenue generation(ads, in-app purchasing, premium services, etc.), now results in malware chasing a user's money rather than their computer resources.

The mobile malware lifecycle can be seen below:


Stage 1: R&D
The initial stage is the Research and Development stage. Here due to the similarity of legitimate and malicious software development the processes followed are the same. A developer will acquire an SDK(Software Development Kit), other development tools, and as much documentation as they can find. After an initial 'Hello World" program is written, the developer will attempt to recreate functionality on the new platform that existed on a previous one. In the case of Android, one would attempt to launch a web browser with http://www.google.com; similar to how they were able to on Windows Mobile. A malware author skilled in developing worms, trojan horses and viruses will figure out ways to achieve the same with the new SDK.

This first stage is about the exploration of new capabilities and for acquiring knowledge. As with legitimate development, this is where malware authors also share their hard won knowledge with others. Unlike previous generations though, the need for revenue will sometimes encourage the authors to move straight to the Profit-Taking stage.

Stage 2: Reuse
Generally after the first stage is passed, a move is made to evade detection. On the most basic level, where script kiddies and under-skilled malware developers lay, evasion takes the form of simple cosmetic changes(strings, colors, filenames, etc.).  This can lead to a flood of very similar variants where only the message displayed to the user is altered("You are hacked by: Skr1pt K1dd1e!").

The Resue stage can benefit from source code developed and released during the R&D stage. One of the first mobile worms, SymbOS/Cabir, had its source released by its author in the computer virus zine 29A. Though this was a release of the worm's original source code it did not result in as many modified variants as would be expected. This was due to the timing of its release and a separate,earlier reverse engineering of the source code by developer Marcos Velasco. Malware developers were able to take the Velasco code and once again through primarily cosmetic changes, recompile and create dozens of Cabir-like variants,

In some cases, as with legitimate developers, malware authors may take the source code as a starting point or example for implementing new functionality for their own productions. As with the R & D stage, the Reuse stage can be affected by the monetary needs of malware authors. Instead of producing new variants, simply adding fucntionality that steals money from users(e.g. Premium Rate SMS, unauthorized in-app purchases,stealing bank account information, etc.) may be the priority for malware authors.

Stage 3: Profit-Taking
The Profit-Taking stage is the most mature stage and can lead to the most interesting(at least for malware analysts and reverse engineers) malware. Evasion of anti-virus/anti-malware software is still a priority but it's also more necessary for other opponents. As methods of earning revenue from victims increases, infected devices become more valuable. On prior Operating Systems a malware author only needed to defeat the Anti-Virus software to survive in the ecosystem. Now if a malware author is successful in running a botnet, they now face competition and attack from other malware authors and organized crime.

This stage has its low hanging fruit in the malware that sends out Premium Rate SMS. These trojans are simple and guarantee a smaller amunt of money to the attacker. Evasion here involves encrypting the SMS numbers and shortcodes from Antimalware software.

More complex attacks involving botnet infections that can deliver false ad-clicks(draining a competitor's ad budget) or fake reveiws(driving up installs for a client's buggy app) make tempting targets. An opponent can take over the command channel of a botnet from the botmaster and redirect the adclicks or re-transfer stolen money.

This competition then leads malware authors to invest funds in countering competition and Antivirus/Antimalware. Profits drive research into new evasion techniques and offensive capabilities(e.g. removing/deleting Antimalware from a device). It also drives attackers to investigate new platforms, which starts the malware lifecycle all over again.

Monday, February 28, 2011

"Write Once, Mobile Malware Anywhere"

from McAfee blog:
"The Zeus (Zbot) crimeware is sold to criminals as a complete toolkit for building custom Trojans, usually to steal banking logins.  The Trojans are generally quite complex; injecting HTML into banking websites on the Internet Explorer and Firefox web browsers, intercepting keystrokes, and grabbing screenshots.  Until a few months ago the Zeus infrastructure targeted only Windows PCs, but the adoption of certain security measures (mTANs sent via SMS) used by some banks caused the criminals to change their tactics.

SymbOS/Zitmo.A was a mobile spyware application used to intercept and forward the mTAN SMS messages sent from an infected user’s bank to an attacker.  This was implemented by the Zeus Trojan for gathering information from victims about their mobile phones so that it could send a targeted download link to them.  The attacker could then change what numbers were monitored by the spyware to go after specific banks.  This particular group of crooks was using SymbOS/Zitmo.A in a targeted attack against Spanish banks.  It was suspected that a Blackberry version of the spyware was also being distributed, but no samples have yet been found."
[...]

Mobile Malware Benefiting From Virtual Machines?
The people behind Zeus are now targeting at least two, if not three, of the major smartphone platforms.  Writing for one smartphone platform can be challenging, writing for multiple devices can be a bigger headache.  By writing a malicious app for the .Net Common Language Runtime(CLR) and Compact Framework, the Zeus authors might be trying to take advantage of coding for virtual machines (VMs).

There are a number of benefits of using VMs for the malware author:
  • maintaining compatibility
    • APIs on the VM will remain the same
  • code reuse
    • working parts of the malware (SMS sending, Bluetooth transfers, etc.) don’t need to be rewritten
  • affecting more devices/OS
    • malware can run on vastly different phones or devices
[...]


Alien Dalvik currently runs on a Nokia N900. Apps run at the same speed as on an Android phone with nearly identical specs. Credit: PRNewsFoto/Myriad Group AG

Given the availability of a common smartphone-based virtual machine (Dalvik on Android/Alien Dalvik on other OS) it would not surprise us if the Zeus authors eventually consolidated their mobile malware onto that single platform.  Instead of just “Angry Birds” one could also get the latest spyware or SMS Trojan.

Wednesday, December 06, 2006

"Want spies with that?"

From McAfee blog:

"We’ve received a sample of a new mobile malware in the MultiDropper family, variant CG. MultiDroppers are like a collection of top 10 hit songs, a ‘hits CD’. They also require about as much creativity. Take a successful hit like SymbOS/Cabir or SymbOS/Commwarrior, mix in a SymbOS/Appdisabler or SymbOS/Skulls.

The trouble with hits CDs is that you probably already own all the albums containing the hits. Maybe you get a bonus song now and then. In the same manner we already detect most of the malware in most mobile MultiDroppers. Every so often we do get the bonus unseen or rare single (malware).

MultiDropper.CG is the first in the series to include spyware, SymbOS/Mobispy.A."

[...]

"Although SymbOS/MultiDropper.CG does not appear likely to be a winner, it does signify a probable switch in malware authors’ goals. Rather than destroying your data and information, they’re stealing it for profit."

Protecting the ‘Metaverse ecosystem’…: Openness is healthy

Meta’s Reality Labs has an opening for “Malware Reverse Engineer” . Not an uncommon role, but this particular one is a bit more specific whe...