Upload
ngodat
View
216
Download
3
Embed Size (px)
Citation preview
Click to edit Master title style
• Click to edit Master text styles
– Second level
• Third level
– Fourth level» Fifth level
September 29th, 2010 Virus Bulletin, Ottawa, Canada
Russian cybercriminals on the
move: profiting from mobile
malware
Senior Malware Analyst, Mobile Research Group Manager
Kaspersky Lab
Denis Maslennikov
Virus Bulletin International Conference, September 29 – October 1
Westin Bayshore Hotel, Vancouver, BC, Canada
Click to edit Master title style
• Click to edit Master text styles
– Second level
• Third level
– Fourth level» Fifth level
September 29th, 2010 Virus Bulletin, Ottawa, Canada
Agenda
09/29/2010 Virus Bulletin International Conference, 2/29
• Statistics
• Evolution of SMS Trojans:
– J2ME Trojans
– Symbian and Windows Mobile Trojans
• The root of all evil
– Affiliate networks
– Anonymity
• How much do they make?
• Today and tomorrow
Click to edit Master title style
• Click to edit Master text styles
– Second level
• Third level
– Fourth level» Fifth level
September 29th, 2010 Virus Bulletin, Ottawa, Canada
‘A long time ago…’
09/29/2010 Virus Bulletin International Conference, 3/29
Trojan-SMS.J2ME.RedBrowser.a
Click to edit Master title style
• Click to edit Master text styles
– Second level
• Third level
– Fourth level» Fifth level
September 29th, 2010 Virus Bulletin, Ottawa, Canada
Statistics
Click to edit Master title style
• Click to edit Master text styles
– Second level
• Third level
– Fourth level» Fifth level
September 29th, 2010 Virus Bulletin, Ottawa, Canada
Mobile malware vs. Trojan-SMS: the numbers
09/29/2010 Virus Bulletin International Conference, 5/29
0
10
20
30
40
50
60
70
80
90
100
Total number of modifications
Trojan-SMS modifications
Source: Kaspersky Lab
Click to edit Master title style
• Click to edit Master text styles
– Second level
• Third level
– Fourth level» Fifth level
September 29th, 2010 Virus Bulletin, Ottawa, Canada
Evolution of SMS TrojansNotable examples
Click to edit Master title style
• Click to edit Master text styles
– Second level
• Third level
– Fourth level» Fifth level
September 29th, 2010 Virus Bulletin, Ottawa, Canada
Evolution overview
09/29/2010 Virus Bulletin International Conference, 7/29
2008-2009• Primitive J2ME Trojans
First half of 2009
• ’Advanced’ J2ME Trojans, primitive Symbian and Windows mobile Trojans
2009-2010
• ‘Advanced’ J2ME Trojans, ‘complex’ Symbian and Windows Mobile Trojans
Click to edit Master title style
• Click to edit Master text styles
– Second level
• Third level
– Fourth level» Fifth level
September 29th, 2010 Virus Bulletin, Ottawa, Canada
Primitive: Trojan-SMS.J2ME.Konov
09/29/2010 Virus Bulletin International Conference, 8/29
• One of the first widespread SMS Trojans:
– Small (1.5 – 6 kB)
– No encryption
– No social engineering
Click to edit Master title style
• Click to edit Master text styles
– Second level
• Third level
– Fourth level» Fifth level
September 29th, 2010 Virus Bulletin, Ottawa, Canada
Konov and VKontakte
09/29/2010 Virus Bulletin International Conference, 9/29
• Spam in social networks
Click to edit Master title style
• Click to edit Master text styles
– Second level
• Third level
– Fourth level» Fifth level
September 29th, 2010 Virus Bulletin, Ottawa, Canada
‘Advanced’: Trojan-SMS.J2ME.VScreener
09/29/2010 Virus Bulletin International Conference, 10/29
• ‘Faulty’ video player
• Must be ‘tuned’ by user:
– Quick press left soft key
• SMSs are sent during ‘tuning’
• Premium rate number and SMS text
are stored in ‘load.bin’ file and encoded
with ADD and ‘0xA’ key
Click to edit Master title style
• Click to edit Master text styles
– Second level
• Third level
– Fourth level» Fifth level
September 29th, 2010 Virus Bulletin, Ottawa, Canada
‘Complex’: Trojan-SMS.SymbOS.Lopsoy
09/29/2010 Virus Bulletin International Conference, 11/29
• Signed SMS Trojan for Symbian S60 3rd edition devices
Click to edit Master title style
• Click to edit Master text styles
– Second level
• Third level
– Fourth level» Fifth level
September 29th, 2010 Virus Bulletin, Ottawa, Canada
Lopsoy ‘source’
09/29/2010 Virus Bulletin International Conference, 12/29
• Article on the website:
– Description of how the Trojan works
– Instructions on ‘How to sign your Trojan’
‘Because of this article
<url> they’re saying I’m
a virus writer. Even
though anyone could
see that my goal was
only to warn people’
Click to edit Master title style
• Click to edit Master text styles
– Second level
• Third level
– Fourth level» Fifth level
September 29th, 2010 Virus Bulletin, Ottawa, Canada
How Lopsoy gets SMS information
09/29/2010 Virus Bulletin International Conference, 13/29
• Connects to author’s URL
• Gets SMS text and premium rate number
http://lou***.ws/devicecontrol.php
Click to edit Master title style
• Click to edit Master text styles
– Second level
• Third level
– Fourth level» Fifth level
September 29th, 2010 Virus Bulletin, Ottawa, Canada
How Lopsoy spreads
09/29/2010 Virus Bulletin International Conference, 14/29
• Various ‘smartphone games’ websites
Click to edit Master title style
• Click to edit Master text styles
– Second level
• Third level
– Fourth level» Fifth level
September 29th, 2010 Virus Bulletin, Ottawa, Canada
‘Complex’: Trojan-SMS.WinCE.Sejweek
09/29/2010 Virus Bulletin International Conference, 15/29
• Connects to web server
• Downloads XML configuration file
• Decodes phone number and interval
• Regularly updates XML file
Click to edit Master title style
• Click to edit Master text styles
– Second level
• Third level
– Fourth level» Fifth level
September 29th, 2010 Virus Bulletin, Ottawa, Canada
How Sejweek spreads
09/29/2010 Virus Bulletin International Conference, 16/29
• Various ‘PDA application’ websites
Click to edit Master title style
• Click to edit Master text styles
– Second level
• Third level
– Fourth level» Fifth level
September 29th, 2010 Virus Bulletin, Ottawa, Canada
The root of all evil
Click to edit Master title style
• Click to edit Master text styles
– Second level
• Third level
– Fourth level» Fifth level
September 29th, 2010 Virus Bulletin, Ottawa, Canada
Trojan-SMS.J2ME.Konov
09/29/2010 Virus Bulletin International Conference, 18/29
Mobile
operator
Subtenant
with ID
1290
‘epbox’
renter
Content
provider
4460
5537
‘epbox’
on 4460
and 5537
‘epbox
1290’ on
4460 and
5537
$10 or
$6 per SMS
Click to edit Master title style
• Click to edit Master text styles
– Second level
• Third level
– Fourth level» Fifth level
September 29th, 2010 Virus Bulletin, Ottawa, Canada
Who are ‘epbox’ and ‘epbox 1290’?
09/29/2010 Virus Bulletin International Conference, 19/29
‘epbox’
renter
‘epbox
1290’
subtenant
Affiliate network
owner(s) (the
partnerka)
Affiliate CAffiliate BAffiliate A
‘epbox N’
subtenant
‘epbox M’
subtenant
Click to edit Master title style
• Click to edit Master text styles
– Second level
• Third level
– Fourth level» Fifth level
September 29th, 2010 Virus Bulletin, Ottawa, Canada
The root of all evil
09/29/2010 Virus Bulletin International Conference, 20/29
• Affiliate network registration form
Name
Website URL
Website name
WMZ and WMR
ICQ (optional)
No
sensitive
data!
Affiliate ID
‘epbox
1290’
Click to edit Master title style
• Click to edit Master text styles
– Second level
• Third level
– Fourth level» Fifth level
September 29th, 2010 Virus Bulletin, Ottawa, Canada
Typical affiliate website
09/29/2010 Virus Bulletin International Conference, 21/29
SMS Trojan
with affiliate
ID
Referrer check
JAR constructor
Remote
serverAffiliate ID
Thousands of websites!
Click to edit Master title style
• Click to edit Master text styles
– Second level
• Third level
– Fourth level» Fifth level
September 29th, 2010 Virus Bulletin, Ottawa, Canada
How much do they make?
Click to edit Master title style
• Click to edit Master text styles
– Second level
• Third level
– Fourth level» Fifth level
September 29th, 2010 Virus Bulletin, Ottawa, Canada
Revenue sharing
09/29/2010 Virus Bulletin International Conference, 23/29
Infected phone
Mobile operator
Content provider
The affiliate
owner(s)Affiliate
31-50% of
SMS price
1-5% of SMS
price
1-5% of SMS
price
40-67% of
SMS priceSMS
Click to edit Master title style
• Click to edit Master text styles
– Second level
• Third level
– Fourth level» Fifth level
September 29th, 2010 Virus Bulletin, Ottawa, Canada
‘Death penalty’
09/29/2010 Virus Bulletin International Conference, 24/29
• Largest mobile affiliate network ‘Perlag’ was fined:
• The fine was equal to 25% of the affiliate network’s
weekly revenue
1,590,000 rubles or $53,000
Weekly income ~$212,000
Monthly income ~$850,000
People were losing at least $1,200,000/month
Click to edit Master title style
• Click to edit Master text styles
– Second level
• Third level
– Fourth level» Fifth level
September 29th, 2010 Virus Bulletin, Ottawa, Canada
Today and tomorrow
Click to edit Master title style
• Click to edit Master text styles
– Second level
• Third level
– Fourth level» Fifth level
September 29th, 2010 Virus Bulletin, Ottawa, Canada
Today
09/29/2010 Virus Bulletin International Conference, 26/29
• Various SMS Trojans for different platforms
• Increasingly sophisticated techniques
• Hundreds of criminalized mobile affiliate networks
• Multi-million dollar losses
• Cybercriminals go unpunished
• Detection problems on simple mobile phones
• Targets: Russian and CIS users
• Reason: legislation loopholes
Click to edit Master title style
• Click to edit Master text styles
– Second level
• Third level
– Fourth level» Fifth level
September 29th, 2010 Virus Bulletin, Ottawa, Canada
Tomorrow (with legislation loopholes)
09/29/2010 Virus Bulletin International Conference, 27/29
• Various SMS Trojans for different platforms
• Increasingly sophisticated techniques
• Hundreds of criminalized mobile affiliate networks
• Multi-million dollar losses
• Cybercriminals go unpunished
• Detection problems on simple mobile phones
• Targets: ?
Click to edit Master title style
• Click to edit Master text styles
– Second level
• Third level
– Fourth level» Fifth level
September 29th, 2010 Virus Bulletin, Ottawa, Canada
New targets
09/29/2010 Virus Bulletin International Conference, 28/29
Click to edit Master title style
• Click to edit Master text styles
– Second level
• Third level
– Fourth level» Fifth level
September 29th, 2010 Virus Bulletin, Ottawa, Canada
Senior Malware Analyst, Mobile Research Group Manager
Kaspersky Lab
http://twitter.com/hEx63
Denis Maslennikov
Virus Bulletin International Conference, September 29 – October 1
Thank you! Questions?