Feeds

Mobile app malware menace grows

Android users at front line of attack

Securing Web Applications Made Simple and Scalable

The number of apps on mobile marketplaces contaminated with malware grew from 80 to 400 during the first half of 2011, according to a study by Lookout Mobile Security.

Android users are particularly at risk of downloading contaminated apps from markets and download sites. Two of the most commonplace threats, DroidDream and GGTracker, were regularly hidden into repackaged gaming apps or utilities and uploaded to Android app marketplaces.

Because of this surge in malicious apps, users are 2.5 times more likely to encounter malware today than at the start of the year, according to Lookout.

Based on data culled from its mobile threat network, Lookout reckons between a half million and a million users were exposed mobile malware in the first six months of 2011.

Threats include malware strains that send text messages from compromised phones. These types of attacks mainly affected Android users in China, Russia and Eastern Europe but arrived in the US last month with a threat called GGTracker.

Web-based threats mean that security risks exist for mobile users outside the Symbian and Android families, the two mobile platforms most commonly targeted by virus writers. Lookout reckons VXers are increasingly looking to redirect surfers to malicious sites contaminated with malware that triggers a download as an alternative to tricking them into opening malicious (Trojanised) applications directly. Update attacks, where an attacker first publishes a legitimate application with no malware – it is only updated with malware components once it has a large user base – have also begun to appear.

"As mobile devices grow in popularity, so do the incentives for attackers," says Kevin Mahaffey, CTO and co-founder of Lookout Mobile Security. "We've seen the prevalence and the level of sophistication of mobile malware attacks evolve significantly in the first six months of 2011. We expect this trend to continue as more and more people adopt mobile devices."

A closer look at the malware security landscape, together with safety tips for users, can be found in Lookout's report here. ®

Mobile application security vulnerability report

More from The Register

next story
LibreSSL RNG bug fix: What's all the forking fuss about, ask devs
Blow to bit-spitter 'tis but a flesh wound, claim team
Manic malware Mayhem spreads through Linux, FreeBSD web servers
And how Google could cripple infection rate in a second
NUDE SNAPS AGENCY: NSA bods love 'showing off your saucy selfies'
Swapping other people's sexts is a fringe benefit, says Snowden
Own a Cisco modem or wireless gateway? It might be owned by someone else, too
Remote code exec in HTTP server hands kit to bad guys
British data cops: We need greater powers and more money
You want data butt kicking, we need bigger boots - ICO
Crooks fling banking Trojan at Japanese smut site fans
Wait - they're doing online banking with an unpatched Windows PC?
NIST told to grow a pair and kick NSA to the curb
Lrn2crypto, oversight panel tells US govt's algorithm bods
prev story

Whitepapers

Reducing security risks from open source software
Follow a few strategies and your organization can gain the full benefits of open source and the cloud without compromising the security of your applications.
Consolidation: The Foundation for IT Business Transformation
In this whitepaper learn how effective consolidation of IT and business resources can enable multiple, meaningful business benefits.
Application security programs and practises
Follow a few strategies and your organization can gain the full benefits of open source and the cloud without compromising the security of your applications.
Boost IT visibility and business value
How building a great service catalog relieves pressure points and demonstrates the value of IT service management.
Consolidation: the foundation for IT and business transformation
In this whitepaper learn how effective consolidation of IT and business resources can enable multiple, meaningful business benefits.