NotebookForums.com › Forums › Off Topic › Mobile Devices Discussion › PikSpam - Another Android Menace and Woe
New Posts  All Forums:Forum Nav:

PikSpam - Another Android Menace and Woe

post #1 of 3
Thread Starter 
Pikspam: An SMS Spam Botnet

The recent discovery of an Android SMS spam botnet by Cloudmark, which is detected by Symantec as Android.Pikspam, has gained media attention. While delivering spam by botnets is nothing new, mobile technology has opened up new attack vectors to cybercriminals who are using the proven attack techniques of social engineering and spam with success on mobile devices.

The attack consists of SMS messages advertising free versions of popular games, or possibly to inform you that you have won a prize. Unsuspecting victims who receive the text messages and follow the link can download a Trojanized app from a third-party website. To activate, a victim is required to click an icon (like the one shown below). The Trojan installation is hidden from the user and traces of its presence removed while it installs the legitimate app onto the user device. Victims only see the advertised app, duping the victim into believing that all is safe.




Once active, the Android.Pikspam Trojan will continually connect to a command-and-control (C&C) server and retrieve text for SMS spam messages along with a list of phone numbers. SMS text messages similar to the one the victim received are then sent from the victim device to the phone numbers previously retrieved, a report is sent back to the C&C server, and the cycle begins again to further spread the Trojan:



Known Android.Pikspam C&C servers include the following:

- pinktrash.mobi
- imperialistic.mobi
- l0rdzs0ldierz.com

The migration of successful attack techniques from computers to the mobile platform has been predicted by many and a trend we will continue to see. If you receive SMS spam, you can forward it to 7726 (S-P-A-M). Also, to stay safe, Symantec recommends you only download apps from well-known and trusted app vendors and install a security app, such as Norton Mobile Security or Symantec Mobile Security, on your device.

source

cheers ...
post #2 of 3
Smartphones: all the woes of desktop computers now in your pocket. winknudge.gif
post #3 of 3
Thread Starter 
^^ Cool observation ... never thought like that myself winknudge.gif

cheers ...
New Posts  All Forums:Forum Nav:
  Return Home
  Back to Forum: Mobile Devices Discussion
NotebookForums.com › Forums › Off Topic › Mobile Devices Discussion › PikSpam - Another Android Menace and Woe