Mobile Malware Skyrocketing

Tuesday, February 21, 2012 @ 03:02 PM gHale

Malicious code written for mobile devices jumped 155 percent in 2011 and has grown more sophisticated, according to a new report.

At the same time, the target platforms of this malware shifted away from Java ME devices in favor of the Android operating system.

Hackers Find Cell Phone Location
Apple Deals with App Privacy Issues
Apple Supplier Hit by Hack
Struggle to Secure Mobile Devices

The trends are not surprising. For years now, security experts have said mobile malware would be the next big thing in cyber threats and the open-platform Android, with its open marketplace for third-party applications, has become an increasingly popular target. But the magnitude of the growth is surprising, said Bob Dix of Juniper Networks.

“It’s a direct result of consumer demand,” said Dix, Juniper’s vice president of government affairs and critical infrastructure protection.

Mobile computing devices have become almost ubiquitous, with shipments of smart handsets reaching 1.6 billion in 2011 and tablets reaching nearly 67 million. At the same time, improved functionality, faster network connections and the growth in applications for these devices have made them attractive to criminals who now are able to monetize their exploits.

The entire market is getting a boost from the generational shift in the workplace where young employees expect to be able to not only access work-related resources with mobile devices, but to use their personal devices for their work. Compounded with applications that enable financial transactions and the fact that few devices are using security technology, it has become “an open invitation to the bad guys,” Dix said.

Spyware makes up the bulk of identified mobile malware, accounting for 63 percent, according to the survey from Juniper’s Mobile Threat Center. This captures data from the device for export to criminals who could exploit it. A more direct money-making scheme is the SMS Trojan, which accounts for 36 percent of mobile malware. This is an application that runs in the background to send SMS messages to premium rate numbers. The owner of the numbers receives the payment, which ends up charged to the user’s account.

The amount of malware written for Android increased exponentially in 2011, going from 400 identified samples in June to more than 13,000 in December.

In 2010, more than 70 percent of identified malware was for Java ME, with another 27 percent for Symbian. BlackBerry, Android and Windows Mobile accounted for a very low amount. In 2011, Android was the top target, with nearly 47 percent of identified malware, and Java ME dropping to 41 percent. Symbian accounted for 11.5 percent.

These figures lack data for the Apple iOS platform because of its closed application marketplace. The same openness that has made Android popular with consumers has also made it popular with malware writers.

“This does not necessarily make it fundamentally more secure,” the report says of iOS. “Jailbreaking” the devices to make them open to third-party downloads also makes them susceptible to exploitation. “Further, there are virtually no meaningful endpoint security products for the iOS platform because Apple does not provide developers with the tools to create them.”

Despite the dominance of Android, the amount of malware for Research In Motion’s BlackBerry and Nokia’s Symbian also grew in 2011. Variants of the ZeuS Trojan have been on BlackBerrys.

Leave a Reply

You must be logged in to post a comment.