Hundreds of Google Play apps create spoofed messages in users' SMS inboxes, Symantec says
The technique could be used for SMS phishing attacks
IDG News Service - About 200 Android applications hosted on Google Play create spoofed SMS messages on the devices on which they are installed, according to security researchers from antivirus vendor Symantec.
This technique can theoretically be used for SMS phishing, a type of attack where users are asked for sensitive information or to subscribe to paid services through rogue SMS messages that appear to originate from a trusted source.
However, the applications detected so far use the technique for other purposes, like displaying advertisements, Mario Ballano, a security researcher at Symantec, said Monday in a blog post.
Last Friday, security researchers from North Carolina State University announced the discovery of a so-called "smishing" (SMS phishing) vulnerability in the Android Open Source Project (AOSP) -- the code that serves as the basis for most Android firmware created by phone manufacturers.
The vulnerability allows a running app without any special permissions to directly write text messages with spoofed sender addresses (telephone numbers) and arbitrary content in the user's SMS inbox.
"We believe such a vulnerability can be readily exploited to launch various phishing attacks," Xuxian Jiang, an associate professor in the Department of Computer Science at NC State University, said at the time. The Google Android Security Team was notified and confirmed that a change will be made in a future Android release to stop this behavior, he said.
However, the code to generate such spoofed SMS messages locally has been publicly documented and used since August 2010, Ballano said.
"We have recorded more than 250 applications that contain code using this technique including 200 that are currently available on Google Play with millions of combined downloads," the researcher said. "Some of the applications use the code to better integrate text messaging with instant messaging or other online services. The vast majority are using an ad-network software development kit (SDK), which pushes ads straight into your SMS inbox."
Even though Symantec has not yet detected an app that used this technique for SMS phishing, users should be wary of the source of any suspicious incoming text messages until Google solves this problem in Android, Ballano said.
- The 20 Best iPhone/iPad Games of 2013 So Far
- 9 Steps to Build Your Personal Brand (and Your Career)
- 7 Consumer Technologies Coming to an Enterprise Near You
- 11 Signs Your IT Project is Doomed
- A walking tour: 33 questions to ask about your company's security
- 15 social media scams
- The 7 elements of a successful security awareness program
- IT Certification Study Tips
- Register for this Computerworld Insider Study Tip guide and gain access to hundreds of premium content articles, cheat sheets, product reviews and more.
- Inquiry Spotlight: Consumer-Facing Identity The challenges of consumer-facing identity management, access management, and authentication differ in ways subtle and dramatic from those of the employee-facing variety.
- IDC Security Infographic From the Era Before security to this current era of empowerment this infographic from Blue coat provides a timeline navigates the rise of...
- Key Drivers: Why CIOs Believe Empowered Users Set the Agenda for Enterprise Security Several years ago, a transformation in IT began to take place; a transformation from an IT-centric view of technology to a business-centric view...
- Security Empowers Business Every magazine article, presentation or blog about the topic seems to start the same way: trying to scare the living daylights out of...
- Bridging HTTP and FTP with FileXpress Internet Server What if you could take an FTP server on your internal network, and allow external users (partners or customers) to securely access it...
- MFT and FileXpress - An Overview Business users and applications exchange files on a regular basis. File transfer is a core part of the flow of business activity. All Security White Papers | Webcasts
Rising salaries boost IT optimism, though not everyone is feeling upbeat. Our survey of 4,000+ IT workers shows who's riding the wave and why. Use our interactive tool and compare your own paycheck. Read more...