Ads by TechWords

See your link here
Receive the latest technology news and information.
Security
Computerworld Daily News (First Look and Wrap-Up)
Computerworld Blogs Newsletter
The Weekly Top 10
Cloud Computing
View all newsletters




Privacy Policy
 

Antivirus firm says it has detected first mobile-phone worm

Cabir not believed to be malicious; international virus writer group 29a is suspected as source

June 14, 2004 12:00 PM ET

IDG News Service - Antivirus company Kaspersky Labs Ltd. said today that it discovered what is believed to be the first computer virus capable of spreading over mobile-phone networks.
Cabir is a network worm that infects phones running Symbian Ltd.'s mobile-phone operating system. No infections have been reported. Cabir may be a proof-of-concept worm from an international group of virus writers known as 29a that's credited with the release of a recent virus, Rugrat, that targets Windows 64-bit operating systems, Moscow-based Kaspersky said.
Cabir spreads between mobile phones using a specially formatted Symbian operating system distribution (or SIS) file disguised as a security management utility. When the infected file is launched, the mobile phone's screen displays the word Caribe, and the worm modifies the Symbian operating system so that Cabir is started each time the phone is turned on.
Once it has infected a mobile phone, Cabir scans for other vulnerable phones using Bluetooth wireless technology, then sends a copy of itself to the first vulnerable phone it finds, Kaspersky said.
Nokia Corp. phones that use the Symbian operating system are vulnerable to the worm. Handsets made by other manufacturers may also be susceptible to Cabir, Kaspersky said.
The virus doesn't appear to have any malicious payload, which is consistent with other viruses, including Rugrat, that are believed to come from the 29a group, Kaspersky said.
In May, researchers from Symantec Corp. identified W634.Rugrat.3344 and linked it to a family of six viruses called W32.Chiton.gen that are all believed to be the work of the same author or group of authors. Each virus in the family demonstrates a different "first ever" infection technique, including W32.Shrug, the first known virus to use the Thread Local Storage structures in Windows NT, 2000 and XP to run virus code, and W32.Chthon, the first virus to run as a native application in Windows NT, 2000 and XP, Cupertino, Calif.-based Symantec said.


Reprinted with permission from

IDG.net
Story copyright 2009 International Data Group. All rights reserved.

Jump to comments

Security

Additional Resources

Xerox
By using solid ink technology only from Xerox, you could save up to 65% by printing color for the cost of black and white. Enter for a chance to WIN a PhaserTM 8860 network color printer!
Microsoft
Save time and mitigate security risk. Deploy it now.
Sybase
In this white paper, IDC analyzes the role of next-generation mobile enterprise platforms as organizations seek a more strategic deployment of mobile solutions.

Learn the important issues you must consider before starting your next mobility initiative. Get your mobility white paper from IDC now, compliments of Sybase.

White Papers & Webcasts

Share our Strength
Download Now  

Managing Secure File Transfer to Save Time, Money and IT Resources
Learn how companies are using innovative technology to overcome these challenges and improve user productivity by offloading e-mail attachments and replacing FTP with...

Security Convergence Equals Network Security Cost Savings
Listen to IBM Internet Security Systems' take on network security convergence.

Disaster Recovery 2008: Reduced Costs and Improved Performance
How long can your Enterprise afford to be without your data? With an accelerated disaster recovery program, you never have to answer this...