Feeds

Your phone may not be spying on you now - BUT it soon will be

Smash it with a hammer now, it's the only way to be sure

Beginner's guide to SSL certificates

Infosec 2013 Tibetan political campaigners targeted by mysterious smartphone-spying software. Eastern European governments' mobiles allegedly snooped on by state-sponsored hackers. Malware feared injected into gadgets during customs inspections.

You've seen these headlines. And according to Kaspersky Lab’s senior malware analyst Denis Maslennikov, there will be more of the same.

In March, Tibetan activists were hit by a highly targeted form of Android malware that accessed their contacts, call logs, text messages, location data, and other information.

Maslennikov, speaking to El Reg, reckons this is nothing new in Android world: he said state-sponsored hackers, in a separate and earlier espionage campaign, infected droid-powered gadgets used by governments in Eastern Europe and beyond - in a spying operation codenamed Red October. Circumstantial evidence to back this claim is laid out in greater detail in this blog post by Kaspersky.

The AndroidOS-Chuli-A Trojan thrown against Tibetan protestors was "not that sophisticated for Android malware", according to Maslennikov, who explained that by targeting smartphones, spies could swipe contact information from the device and its SIM card that would be hard to obtain with other techniques.

Maslennikov described last month's Tibetan attack as a shape of things to come, rather than a one-off. Infiltration attempts using combinations of social engineering skills, zero-day vulnerabilities and exploits are more and more likely.

Meanwhile, the commercial FinFisher (AKA FinSpy) application, produced by Anglo-German firm Gamma International and marketed as a “lawful interception” suite, allows cops and spooks to infiltrate and monitor computers used by suspected criminals. It has reportedly been bought by state agencies in the Middle East and Southeast Asia to spy on human rights activists and other targets.

A recent report by security researchers from The Citizen Lab details the discovery of a mobile phone version of FinSpy. This features GPS tracking, the ability to snoop on spoken conversations taking place close to the hacked handset, and the power to lift text messages from compromised smartphones.

Today, state-backed cyber-spies will "try to attack everything", according to Maslennikov, who said that Mac computers were penetrated in order to snoop on Tibetan and Uyghur political activists. And it's been widely suspected that smartphones passing through Chinese customs sometimes come out the other side with unwelcome extras.

"High-level attackers will target everything possible," he added. "We must protect all kinds of devices. Please don't think your smartphone or tablet is safer than your PC." ®

Top 5 reasons to deploy VMware with Tegile

More from The Register

next story
Regin: The super-spyware the security industry has been silent about
NSA fingered as likely source of complex malware family
Why did it take antivirus giants YEARS to drill into super-scary Regin? Symantec responds...
FYI this isn't just going to target Windows, Linux and OS X fans
Privacy bods offer GOV SPY VICTIMS a FREE SPYWARE SNIFFER
Looks for gov malware that evades most antivirus
Patch NOW! Microsoft slings emergency bug fix at Windows admins
Vulnerability promotes lusers to domain overlords ... oops
HACKERS can DELETE SURVEILLANCE DVRS remotely – report
Hikvision devices wide open to hacking, claim securobods
'Regin': The 'New Stuxnet' spook-grade SOFTWARE WEAPON described
'A degree of technical competence rarely seen'
Astro-boffins start opening universe simulation data
Got a supercomputer? Want to simulate a universe? Here you go
You stupid BRICK! PCs running Avast AV can't handle Windows fixes
Fix issued, fingers pointed, forums in flames
prev story

Whitepapers

Go beyond APM with real-time IT operations analytics
How IT operations teams can harness the wealth of wire data already flowing through their environment for real-time operational intelligence.
Forging a new future with identity relationship management
Learn about ForgeRock's next generation IRM platform and how it is designed to empower CEOS's and enterprises to engage with consumers.
10 threats to successful enterprise endpoint backup
10 threats to a successful backup including issues with BYOD, slow backups and ineffective security.
High Performance for All
While HPC is not new, it has traditionally been seen as a specialist area – is it now geared up to meet more mainstream requirements?
Security and trust: The backbone of doing business over the internet
Explores the current state of website security and the contributions Symantec is making to help organizations protect critical data and build trust with customers.