ZDNet UK


Skip to Main Content

ZDNet.co.uk - Winner of Best Business Website 2007
  1. Home
  2. News
  3. Blogs
  4. Reviews
  5. Prices
  6. Resources
  7. Community
  8. My ZDNet

 

ZDNet UK RSS Feeds


IT Jobs

Security threats Toolkit

CommWarrior guns for Nokias

Matt Hines CNET News.com

Published: 08 Mar 2005 09:00 GMT

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

Antivirus researchers are investigating a new Trojan horse that could prove to be a more pervasive threat to mobile phones than Cabir.

The malicious software, dubbed "CommWarrior" and described as a virus by some antivirus companies, takes aim at the version of the Symbian operating system running on Nokia Series 60 handsets. F-Secure, SimWorks International and other security providers issued reports about the threat on Monday.

CommWarrior attempts to spread by sending messages via Bluetooth wireless connections and Multimedia Message Service — different from the Cabir virus, which only used Bluetooth to proliferate.

While many modern phones are capable of sending MMS messages CommWarrior only affects Nokia Series 60 phones.

As MMS messages can be sent worldwide, CommWarrior has a greater reach than viruses that spread using the short-range Bluetooth technology, researchers said.

"At its best replication speed, Cabir can only spread as quickly as planes fly," said Mikko Hyppönen, antivirus research director at Finland-based F-Secure. "But MMS viruses are more comparable to email worms like Bagle, MyDoom, Sobig and others. An MMS threat can travel around the world in hours, so in that regard, it's much more dangerous."

A representative for United Kingdom-based Symbian said the company is aware of the problem and researching the threat with Nokia and its security partners. Nokia could not be immediately reached for comment.

CommWarrior infects the telephone directory software in the Nokia handsets. It randomly selects one directory profile at a time and sends a copy of itself to that person. It can be sent to any kind of wireless gadget or computer, but if that device does not run the Symbian Series 60 software, it will not be infected. A recipient also has to accept and download CommWarrior in order for the Trojan to launch itself.

The Trojan uses more than 20 different messages to try to lure users into opening its file, including text designed to look like legitimate software updates from Symbian, or even pornographic photographs.

CommWarrior has been seen in the wild since the beginning of this year, Hyppönen said. An element of the program that causes it to sleep for an undetermined period of time before attempting to spread itself may have helped slow its distribution, he said.

Researchers have noted two versions of the threat thus far, with the only major difference in the strains being the overall file size. Hyppönen said there is some Russian-language text hidden inside the files, a clue that the threat may have been developed in that region.

An individual claiming responsibility for creating the threat has made it available for download via a Web site. The site offers no further information about the purported writer of the Trojan.

Based on a lack of consumer reports on the attack, researchers believe that CommWarrior has yet to infect a large number of devices. One reason for the relative dearth of infections may be that the Trojan is trying to send itself to large numbers of landline phones, as it cannot differentiate between mobile and traditional phone numbers.

  • Email
  • Trackback
  • Clip Link
  • Print friendly Print with Dell

Did you find this article useful?
158 out of 293 people found this useful



Company/Topic Alerts

Create a new alert from the list below:






Related Jobs

S&P (Security) IT Specialist

Non Technical skills - Security methods and practices - Data encryption technologies and products - Operational security and trust models - Physical ...

Drive Test / Field Trials Engineer - Mobile Handsets - Berkshire

My client, a leading Telecoms company based in Berkshire are currently recruiting for a Field Trials Engineer to work in a small team responsible for ...

Procurement Consultant / Senior Consultant

Procurement Consultant / Senior Consultant Job ID GBS-0051912 Job type Full-time Regular Work country United Kingdom Work city London Job role ...

Featured Talkback

What was achieved there is recognised to be of fundamental importance to both winning the war (Churchill visited to say 'thank you' to them) and the development of the computer. Maybe Bill Gates doesn't want to support this museum because it underlines where electronic computing started i.e. here, not the U.S.

By: 1000103773

Read full story:
Bletchley Park faces bleak future

Sentry Posts Blog

Mobile Security Expert: Your Camera Ph...

Mobile Security Expert: Your Camera Phone Got Hacked Author: Eric Everson, Founder MyMobiSafe.com Have you ever heard someone say “I’d like to be a fly on the wall in that room.”?... More

Post a comment

Skype - The Roach Motel

Here is an interesting article from The National Business Review, pointing out once again that you can never delete a Skype account. Never. Period. This is something I am familiar... More

Post a comment

The vPhone: Why Visa Should Go Mobile

The vPhone: Why Visa Should Go Mobile Author: Eric Everson, Founder MyMobiSafe.com With all of the success of Apple’s iPhone, there is a growing case to support a company like Visa... More

Post a comment