Feeds

Vodafone Spain supplies pre-Mariposa'd smartphone (again)

Botnet-ready? Excellent

Beginner's guide to SSL certificates

Vodafone Spain has again supplied a HTC Magic smartphone that came pre-infected with the Mariposa botnet client and other malware crud.

The second incident, involving an Android-based phone supplied to a researcher at S21Sec, comes a week after the mobile phone giant supplied the same type of infection on the identical model of phone to a worker at Spanish anti-virus firm Panda Security.

The S21Sec pre-pwned smartphone kerfuffle undermines Vodafone's assurances at the time of the Panda flap that the incident was "isolated and local". Both smartphones were ordered at around the same time towards the beginning of March.

We spoke to Vodafone on Wednesday, making it aware of the second HTC Magic/Mariposa infection in Iberia. Vodafone stuck by its original line that the problem was "isolated and local" but added that it hadn't experienced the problem outside of Spain. A spokesman added that its investigation is continuing. "Even one infection is one too many," he added.

Dos veces

The S21Sec worker detected the malware after he plugged it into his PC using a copy of AVG's scanner. Aware of Panda's previous work, he forwarded an infected microSD drive to PandaLabs Pedro Bustamante, who carried out an analysis published here.

"According to the dates of the files, it seems his Vodafone HTC Magic was loaded with the Mariposa bot client on March 1st, 2010 at 19:07, a little over a week before the phone was delivered to him directly from Vodafone," Bustamante writes.

"The Mariposa botnet client itself is exactly the same as reported last week, with the same nickname and same Command & Control servers."

The circumstances of the infection point to problems in Vodafone's QA or with a specific batch of phones rather than a stray infection of a refurbished phone.

Oddly, Vodafone UK reportedly discontinued distribution of the HTC Magic two days after the original Panda-related incident in favour of supplying HTC Tattoo as its sole Android device. Vodapone Spain continues to supply the HTC Magic, however. ®

Secure remote control for conventional and virtual desktops

More from The Register

next story
Of COURSE Stephen Elop's to blame for Nokia woes, says author
'Google did have some unique propositions for Nokia'
FCC, Google cast eye over millimetre wireless
The smaller the wave, the bigger 5G's chances of success
It's even GRIMMER up North after MEGA SKY BROADBAND OUTAGE
By 'eck! Eccles cake production thrown into jeopardy
Mobile coverage on trains really is pants
You thought it was just *insert your provider here*, but now we have numbers
Don't mess with Texas ('cos it's getting Google Fiber and you're not)
A bit late, but company says 1Gbps Austin network almost ready to compete with AT&T
prev story

Whitepapers

Forging a new future with identity relationship management
Learn about ForgeRock's next generation IRM platform and how it is designed to empower CEOS's and enterprises to engage with consumers.
Cloud and hybrid-cloud data protection for VMware
Learn how quick and easy it is to configure backups and perform restores for VMware environments.
Three 1TB solid state scorchers up for grabs
Big SSDs can be expensive but think big and think free because you could be the lucky winner of one of three 1TB Samsung SSD 840 EVO drives that we’re giving away worth over £300 apiece.
Reg Reader Research: SaaS based Email and Office Productivity Tools
Read this Reg reader report which provides advice and guidance for SMBs towards the use of SaaS based email and Office productivity tools.
Security for virtualized datacentres
Legacy security solutions are inefficient due to the architectural differences between physical and virtual environments.