Mobile enterprise management tools are targeted by spyphones, researchers warn
iOS devices are targeted the most, they said
IDG News Service - Enterprises that use mobile device management (MDM) systems to protect their corporate data on employees' mobile phones are not safe from attacks from spyphones, researchers warned at BlackHat Europe on Thursday.
Over the next five years, 65 percent of enterprises will adopt a mobile device management (MDM) system for corporate users, technology research company Gartner predicted last October. Companies will use the systems to manage network traffic and corporate data on smartphones and tablets, which nowadays are often owned by employees and used for both private and corporate tasks.
Companies are using MDM systems to protect their data, but they must be aware that while the systems are useful, they don't provide full security and can be targeted by so-called spyphones, warned Daniel Brodie, senior security researcher at the Israeli security company Lacoon Security, and Michael Shaulov, CEO and co-founder of the company, at the BlackHat conference in Amsterdam.
MDM systems try to tackle security issues by providing a "secure container" on mobile devices, encrypting the part of the mobile device that handles business data, as well as offering the possibility to remotely wipe or lock that section if a phone is stolen or an employee quits. However, common MDM security offerings can be circumvented by planting surveillance tools without the users knowledge on a phone, turning it into a spyphone, Brodie told a crowd of conference attendees.
A survey conducted by Lacoon in cooperation with global cellular network providers showed that about one in 1,000 phones was a spyphone, according to Brodie's research paper. Of 175 compromised devices found, 52 percent was attributed to Apple's iOS, 35 percent to Android phones, 7 percent to Nokia phones and 6 percent to other devices, he said.
"This is a very alarming number," Brodie said. The problem with spyphones is that while the software is installed on a single device, it is used to target whole organizations for espionage purposes, Brodie said. And as such, the impact of a spyphone attack on an organization can be "extremely high," he added.
Most spyphones are used for recording confidential phone calls and board meetings, tracking locations, extracting call logs as well as text messages and voice memos, and snooping on corporate emails and application data, Brodie said.
Secure containers of MDM systems can be bypassed in order to install spyphone software. On Android devices this can be done by publishing a seemingly innocent application in an Android market. Once the victim has installed the app, the app refers to the malicious code, which is then downloaded, the researchers said. After this, the spyphone creates a hidden binary and uses it for privileged operations, such as reading mobile logs.
- 15 Non-Certified IT Skills Growing in Demand
- How 19 Tech Titans Target Healthcare
- Twitter Suffering From Growing Pains (and Facebook Comparisons)
- Agile Comes to Data Integration
- Slideshow: 7 security mistakes people make with their mobile device
- iOS vs. Android: Which is more secure?
- 11 sure signs you've been hacked
- Mobile Policy Checklist Here's what to consider when putting together a mobile policy designed to support a highly productive workforce.
- Mobile Applications Case Study: 8 Billion Transactions a Day The story documents how the online brokerage company tradeMONSTER created a custom mobile app and the success gleaned from this initiative. Also covered...
- Securing BYOD Mobile computing is becoming so ubiquitous that people no longer bat an eye seeing someone working two devices simultaneously. Individuals and organizations are...
- The Case for Mobile Apps Today's mobile apps turn handheld devices into e-book readers, portable navigation systems, digital wallets and more. And for organizations with mobile workers, they...
- Live Webcast On-demand webinar: "Mobility Mayhem: Balancing BYOD with Enterprise Security" Check out this on-demand webinar to hear Sophos senior security expert John Shier deep dive into how BYOD impacts your enterprise security strategy...
- Live Webcast Unmasking the Differences between Consumer and Enterprise File Sync & Share The consumerization of IT combined with the rapid pace of the modern mobile workplace is forcing enterprise IT teams to evaluate file sync...
- Live Webcast Workforce Mobilization for Improved Productivity A mobility research director from Aberdeen discusses reasons for extending legacy applications to mobile devices, and an integration strategist from Attachmate shows how...
- Mobile Apps and Devices Slash Customer Cycle Time Consolidated Engineering Laboratories' field employees used to collect data on triplicate forms that were sometimes hard to read and difficult to manage. After...
- CDW Integrates with Google Apps for Cloud Collaboration Through a partnership with Google and Esna Technologies, CDW has rolled out native access to the CDW Cloud Collaboration suite within Google Apps. All Mobile/Wireless White Papers | Webcasts