Jimmy Shah
Jimmy Shah is a Mobile Security Researcher for McAfee, specializing in analysis of mobile threats on existing ...
#SecChat $1 million guarantee 12 Scams of Christmas access to live fraud resolution agents Acquisition Alex Thurber Android antivirus Apple botnet Channel Partners cloud security Compliance Consumer counter identity theft credit card fraud and protection credit fraud alerts credit monitoring credit monitoring and resolution critical infrastructure Cyber Security Mom cyberbullying Cybercrime cybermom data breach data center data center security Data Protection Dave DeWalt DLP Email & Web Security embedded encryption Endpoint Protection enterprise facebook fake anti-virus software Family Safety Friday Security Highlights global threat intelligence google government Hacktivism how to talk to kids how to talk to teens identity fraud identity fraud scams identity protection identity protection $1 million guarantee identity protection fraud identity protection surveillance identity surveillance identity theft identity theft expert identity theft fraud identity theft protection identity theft protection product Identity thieves and cybercriminals intel iphone kids online behavior lost wallet protection malware McAfee McAfee Channel McAfee Family Protection McAfee Identity Protection McAfee Initiative to Fight Cybercrime McAfee Labs McAfee security products Mid-Market Mobile mobile malware mobile security monitor credit and personal information Network Security online personal data protection online safety Operation Aurora PCI personal identity theft fraud personal information loss personal information protection phishing privacy proactive identity protection proactive identity surveillance Public Sector restore credit and personal identity Risk and Compliance scam scams scareware security smartphones social media social networking social networks spam Stuxnet twitter vulnerability Web 2.0 work with victim restore identity
|
|
A Window Mobile PocketPC trojan that disables Windows Mobile application installation security has been discovered in China.
WinCE/InfoJack sends the infected device’s serial number, operating system and other information to the author of the trojan. It also leaves the infected mobile device vulnerable by allowing silent installation of malware. The trojan modifies the infected device’s security setting to allow unsigned applications to be installed without a warning.
The trojan was packed inside a number of legitimate installation files and distributed widely. It has been distributed with Google Maps, applications for stock trading, and a collection of games.

WinCE/InfoJack was created by a specific website. The website may have hired someone to create the trojan and distribute it to other sites. The maintainer of the website claims that the software was just necessary to collect information on the types of mobiles used to access their site. That would be easier to believe if they had notified the user prior to installation or if they had provided some sort of uninstallation method.

WinCE/InfoJack has a number of features that show its malicious intent:

That last feature, allowing silent installation of an unsigned app, is used by WinCE/InfoJack to auto update itself. It also leaves the mobile open to other malware being installed silently. Fortunately the trojan’s website is no longer reachable, due in part to an investigation by local law enforcement.
|
|
I was worried about the security of my Mobile phone so I looked into the antivirus and encryption software currently available. I went with Airscanner (Airscanner.com), which has different combo packages depending on what you’re looking for. They even have a 30 day trial period, which is great if you’re non-commital… but of course once I tried it I had to have it.
Truly truly i wrote today, we are in the process to errors and problems shifting paradigms. We are unable to combat desktops, viruses, worms, and Trojans, these epidemics are finding there ways to all the new technological innovations.
Solutions maybe the creations of protective shields by the OS and browsers producers, centralised active roles by all the mobiles telecommunications providers and centralised mobile users awareness.
We have to find solutions to many problems because the era of embedded systems utilisation is here and growing in magitudes.
in response to OSB,
You are joking right? Almost all new PDA phones are made with Windows CE in them. They are always connected to the Internet. Yes, it may be time to have Anti-Virus software on your PDA as stupid as it sounds.
Sounds like a fake to me.
It is such a difficult platform to exploit in terms of connectivity.
Pocket pcs are not as PCs always connected. It is not worth to consume that much precious space and memory, which can be easily spotted since the pda would be useless.
Does the McAfee PDA AV product stop this thing? Or does it just find it and tell you you are hosed?
Looking at the screen shot – the date of the autorun file is the 25th may 2006! Nearly 2 years ago, have McAfee known about this for that long and have only now decided to publicise it Our mobile antivirus software sales are flagging, lets drum up some publicity by saying theres a trojan about?
I am a Chinese.I can’t find it in Chinese website.Where do you find it?Maybe it’s the InfoStealer.A two months ago,isn’t it?
Where can I get the Trojan?
The thing that most upsets me is that McAfee didn’t find it right to publish the URL of the website that is spreading the virus.
We have the right to know that both for not going there and also for warning our readers not to visit this site anymore.
So, are we saying here that customers who downloaded Google Maps from Google have this malware?
Or that someone repackaged Google Maps, added their malware, and redistributed it?
Check Blackberry’s track-record dude when it comes to things like these!
Oh Great!!! … and having hear the good news I don’t hear anything about what we can do about it. Can we know what applications it was installed in? Can we know how it can be removed… ie scrape and reinstall? Can we actually get al itlle real information about this problem???
Dr. Bontchev…
It is a virus! But it hides inside and behind other install files. If I have my lexicon straight, a virus moves by human transmittal. A worm moves by automatic transmittal. A trojan pretends to be something it isn’t.
Ultimately, it’s malware, so the issue is a sidebar at best…
Does the trojan works on symbian S60 3rd edition?
Wow, the sound is so dangerous,
its time for Palm Inc. To develop new OS, Palm OS Cobalt is safer than WM.
Regards,
-rosgani-
and I was just reading the other day not to worry about installing ppc antivirus due to nothing really warranting heavy software installations
Why do you classify it as a Trojan?? According to the above description, if run on the device, it installs itself on the memory card. If a memory card containing it is inserted into a clean device, it runs automatically from the card and installs itself on the device.
Sounds like a full-blown virus to me.
Submit your own comments / message for this post