29
Click to edit Master title style Click to edit Master text styles Second level Third level Fourth level » Fifth level September 29 th , 2010 Virus Bulletin, Ottawa, Canada Russian cybercriminals on the move: profiting from mobile malware Senior Malware Analyst, Mobile Research Group Manager Kaspersky Lab Denis Maslennikov Virus Bulletin International Conference, September 29 October 1 Westin Bayshore Hotel, Vancouver, BC, Canada

Third level Fourth level Russian ... - Virus Bulletin · –Symbian and Windows Mobile Trojans ... 2010 Virus Bulletin, Ottawa, Canada Mobile malware vs. Trojan-SMS: ... •Detection

  • Upload
    ngodat

  • View
    216

  • Download
    3

Embed Size (px)

Citation preview

Click to edit Master title style

• Click to edit Master text styles

– Second level

• Third level

– Fourth level» Fifth level

September 29th, 2010 Virus Bulletin, Ottawa, Canada

Russian cybercriminals on the

move: profiting from mobile

malware

Senior Malware Analyst, Mobile Research Group Manager

Kaspersky Lab

Denis Maslennikov

Virus Bulletin International Conference, September 29 – October 1

Westin Bayshore Hotel, Vancouver, BC, Canada

Click to edit Master title style

• Click to edit Master text styles

– Second level

• Third level

– Fourth level» Fifth level

September 29th, 2010 Virus Bulletin, Ottawa, Canada

Agenda

09/29/2010 Virus Bulletin International Conference, 2/29

• Statistics

• Evolution of SMS Trojans:

– J2ME Trojans

– Symbian and Windows Mobile Trojans

• The root of all evil

– Affiliate networks

– Anonymity

• How much do they make?

• Today and tomorrow

Click to edit Master title style

• Click to edit Master text styles

– Second level

• Third level

– Fourth level» Fifth level

September 29th, 2010 Virus Bulletin, Ottawa, Canada

‘A long time ago…’

09/29/2010 Virus Bulletin International Conference, 3/29

Trojan-SMS.J2ME.RedBrowser.a

Click to edit Master title style

• Click to edit Master text styles

– Second level

• Third level

– Fourth level» Fifth level

September 29th, 2010 Virus Bulletin, Ottawa, Canada

Statistics

Click to edit Master title style

• Click to edit Master text styles

– Second level

• Third level

– Fourth level» Fifth level

September 29th, 2010 Virus Bulletin, Ottawa, Canada

Mobile malware vs. Trojan-SMS: the numbers

09/29/2010 Virus Bulletin International Conference, 5/29

0

10

20

30

40

50

60

70

80

90

100

Total number of modifications

Trojan-SMS modifications

Source: Kaspersky Lab

Click to edit Master title style

• Click to edit Master text styles

– Second level

• Third level

– Fourth level» Fifth level

September 29th, 2010 Virus Bulletin, Ottawa, Canada

Evolution of SMS TrojansNotable examples

Click to edit Master title style

• Click to edit Master text styles

– Second level

• Third level

– Fourth level» Fifth level

September 29th, 2010 Virus Bulletin, Ottawa, Canada

Evolution overview

09/29/2010 Virus Bulletin International Conference, 7/29

2008-2009• Primitive J2ME Trojans

First half of 2009

• ’Advanced’ J2ME Trojans, primitive Symbian and Windows mobile Trojans

2009-2010

• ‘Advanced’ J2ME Trojans, ‘complex’ Symbian and Windows Mobile Trojans

Click to edit Master title style

• Click to edit Master text styles

– Second level

• Third level

– Fourth level» Fifth level

September 29th, 2010 Virus Bulletin, Ottawa, Canada

Primitive: Trojan-SMS.J2ME.Konov

09/29/2010 Virus Bulletin International Conference, 8/29

• One of the first widespread SMS Trojans:

– Small (1.5 – 6 kB)

– No encryption

– No social engineering

Click to edit Master title style

• Click to edit Master text styles

– Second level

• Third level

– Fourth level» Fifth level

September 29th, 2010 Virus Bulletin, Ottawa, Canada

Konov and VKontakte

09/29/2010 Virus Bulletin International Conference, 9/29

• Spam in social networks

Click to edit Master title style

• Click to edit Master text styles

– Second level

• Third level

– Fourth level» Fifth level

September 29th, 2010 Virus Bulletin, Ottawa, Canada

‘Advanced’: Trojan-SMS.J2ME.VScreener

09/29/2010 Virus Bulletin International Conference, 10/29

• ‘Faulty’ video player

• Must be ‘tuned’ by user:

– Quick press left soft key

• SMSs are sent during ‘tuning’

• Premium rate number and SMS text

are stored in ‘load.bin’ file and encoded

with ADD and ‘0xA’ key

Click to edit Master title style

• Click to edit Master text styles

– Second level

• Third level

– Fourth level» Fifth level

September 29th, 2010 Virus Bulletin, Ottawa, Canada

‘Complex’: Trojan-SMS.SymbOS.Lopsoy

09/29/2010 Virus Bulletin International Conference, 11/29

• Signed SMS Trojan for Symbian S60 3rd edition devices

Click to edit Master title style

• Click to edit Master text styles

– Second level

• Third level

– Fourth level» Fifth level

September 29th, 2010 Virus Bulletin, Ottawa, Canada

Lopsoy ‘source’

09/29/2010 Virus Bulletin International Conference, 12/29

• Article on the website:

– Description of how the Trojan works

– Instructions on ‘How to sign your Trojan’

‘Because of this article

<url> they’re saying I’m

a virus writer. Even

though anyone could

see that my goal was

only to warn people’

Click to edit Master title style

• Click to edit Master text styles

– Second level

• Third level

– Fourth level» Fifth level

September 29th, 2010 Virus Bulletin, Ottawa, Canada

How Lopsoy gets SMS information

09/29/2010 Virus Bulletin International Conference, 13/29

• Connects to author’s URL

• Gets SMS text and premium rate number

http://lou***.ws/devicecontrol.php

Click to edit Master title style

• Click to edit Master text styles

– Second level

• Third level

– Fourth level» Fifth level

September 29th, 2010 Virus Bulletin, Ottawa, Canada

How Lopsoy spreads

09/29/2010 Virus Bulletin International Conference, 14/29

• Various ‘smartphone games’ websites

Click to edit Master title style

• Click to edit Master text styles

– Second level

• Third level

– Fourth level» Fifth level

September 29th, 2010 Virus Bulletin, Ottawa, Canada

‘Complex’: Trojan-SMS.WinCE.Sejweek

09/29/2010 Virus Bulletin International Conference, 15/29

• Connects to web server

• Downloads XML configuration file

• Decodes phone number and interval

• Regularly updates XML file

Click to edit Master title style

• Click to edit Master text styles

– Second level

• Third level

– Fourth level» Fifth level

September 29th, 2010 Virus Bulletin, Ottawa, Canada

How Sejweek spreads

09/29/2010 Virus Bulletin International Conference, 16/29

• Various ‘PDA application’ websites

Click to edit Master title style

• Click to edit Master text styles

– Second level

• Third level

– Fourth level» Fifth level

September 29th, 2010 Virus Bulletin, Ottawa, Canada

The root of all evil

Click to edit Master title style

• Click to edit Master text styles

– Second level

• Third level

– Fourth level» Fifth level

September 29th, 2010 Virus Bulletin, Ottawa, Canada

Trojan-SMS.J2ME.Konov

09/29/2010 Virus Bulletin International Conference, 18/29

Mobile

operator

Subtenant

with ID

1290

‘epbox’

renter

Content

provider

4460

5537

‘epbox’

on 4460

and 5537

‘epbox

1290’ on

4460 and

5537

$10 or

$6 per SMS

Click to edit Master title style

• Click to edit Master text styles

– Second level

• Third level

– Fourth level» Fifth level

September 29th, 2010 Virus Bulletin, Ottawa, Canada

Who are ‘epbox’ and ‘epbox 1290’?

09/29/2010 Virus Bulletin International Conference, 19/29

‘epbox’

renter

‘epbox

1290’

subtenant

Affiliate network

owner(s) (the

partnerka)

Affiliate CAffiliate BAffiliate A

‘epbox N’

subtenant

‘epbox M’

subtenant

Click to edit Master title style

• Click to edit Master text styles

– Second level

• Third level

– Fourth level» Fifth level

September 29th, 2010 Virus Bulletin, Ottawa, Canada

The root of all evil

09/29/2010 Virus Bulletin International Conference, 20/29

• Affiliate network registration form

Name

Email

Website URL

Website name

WMZ and WMR

ICQ (optional)

No

sensitive

data!

Affiliate ID

‘epbox

1290’

Click to edit Master title style

• Click to edit Master text styles

– Second level

• Third level

– Fourth level» Fifth level

September 29th, 2010 Virus Bulletin, Ottawa, Canada

Typical affiliate website

09/29/2010 Virus Bulletin International Conference, 21/29

SMS Trojan

with affiliate

ID

Referrer check

JAR constructor

Remote

serverAffiliate ID

Thousands of websites!

Click to edit Master title style

• Click to edit Master text styles

– Second level

• Third level

– Fourth level» Fifth level

September 29th, 2010 Virus Bulletin, Ottawa, Canada

How much do they make?

Click to edit Master title style

• Click to edit Master text styles

– Second level

• Third level

– Fourth level» Fifth level

September 29th, 2010 Virus Bulletin, Ottawa, Canada

Revenue sharing

09/29/2010 Virus Bulletin International Conference, 23/29

Infected phone

Mobile operator

Content provider

The affiliate

owner(s)Affiliate

31-50% of

SMS price

1-5% of SMS

price

1-5% of SMS

price

40-67% of

SMS priceSMS

Click to edit Master title style

• Click to edit Master text styles

– Second level

• Third level

– Fourth level» Fifth level

September 29th, 2010 Virus Bulletin, Ottawa, Canada

‘Death penalty’

09/29/2010 Virus Bulletin International Conference, 24/29

• Largest mobile affiliate network ‘Perlag’ was fined:

• The fine was equal to 25% of the affiliate network’s

weekly revenue

1,590,000 rubles or $53,000

Weekly income ~$212,000

Monthly income ~$850,000

People were losing at least $1,200,000/month

Click to edit Master title style

• Click to edit Master text styles

– Second level

• Third level

– Fourth level» Fifth level

September 29th, 2010 Virus Bulletin, Ottawa, Canada

Today and tomorrow

Click to edit Master title style

• Click to edit Master text styles

– Second level

• Third level

– Fourth level» Fifth level

September 29th, 2010 Virus Bulletin, Ottawa, Canada

Today

09/29/2010 Virus Bulletin International Conference, 26/29

• Various SMS Trojans for different platforms

• Increasingly sophisticated techniques

• Hundreds of criminalized mobile affiliate networks

• Multi-million dollar losses

• Cybercriminals go unpunished

• Detection problems on simple mobile phones

• Targets: Russian and CIS users

• Reason: legislation loopholes

Click to edit Master title style

• Click to edit Master text styles

– Second level

• Third level

– Fourth level» Fifth level

September 29th, 2010 Virus Bulletin, Ottawa, Canada

Tomorrow (with legislation loopholes)

09/29/2010 Virus Bulletin International Conference, 27/29

• Various SMS Trojans for different platforms

• Increasingly sophisticated techniques

• Hundreds of criminalized mobile affiliate networks

• Multi-million dollar losses

• Cybercriminals go unpunished

• Detection problems on simple mobile phones

• Targets: ?

Click to edit Master title style

• Click to edit Master text styles

– Second level

• Third level

– Fourth level» Fifth level

September 29th, 2010 Virus Bulletin, Ottawa, Canada

New targets

09/29/2010 Virus Bulletin International Conference, 28/29

Click to edit Master title style

• Click to edit Master text styles

– Second level

• Third level

– Fourth level» Fifth level

September 29th, 2010 Virus Bulletin, Ottawa, Canada

Senior Malware Analyst, Mobile Research Group Manager

Kaspersky Lab

[email protected]

http://twitter.com/hEx63

Denis Maslennikov

Virus Bulletin International Conference, September 29 – October 1

Thank you! Questions?