Antivirus firm says it has detected first mobile-phone worm
Cabir not believed to be malicious; international virus writer group 29a is suspected as source
June 14, 2004 12:00 PM ETIDG News Service -
Antivirus company Kaspersky Labs Ltd. said today that it discovered what is believed to be the first computer virus capable of spreading over mobile-phone networks.
Cabir is a network worm that infects phones running Symbian Ltd.'s mobile-phone operating system. No infections have been reported. Cabir may be a proof-of-concept worm from an international group of virus writers known as 29a that's credited with the release of a recent virus, Rugrat, that targets Windows 64-bit operating systems, Moscow-based Kaspersky said.
Cabir spreads between mobile phones using a specially formatted Symbian operating system distribution (or SIS) file disguised as a security management utility. When the infected file is launched, the mobile phone's screen displays the word Caribe, and the worm modifies the Symbian operating system so that Cabir is started each time the phone is turned on.
Once it has infected a mobile phone, Cabir scans for other vulnerable phones using Bluetooth wireless technology, then sends a copy of itself to the first vulnerable phone it finds, Kaspersky said.
Nokia Corp. phones that use the Symbian operating system are vulnerable to the worm. Handsets made by other manufacturers may also be susceptible to Cabir, Kaspersky said.
The virus doesn't appear to have any malicious payload, which is consistent with other viruses, including Rugrat, that are believed to come from the 29a group, Kaspersky said.
In May, researchers from Symantec Corp. identified W634.Rugrat.3344 and linked it to a family of six viruses called W32.Chiton.gen that are all believed to be the work of the same author or group of authors. Each virus in the family demonstrates a different "first ever" infection technique, including W32.Shrug, the first known virus to use the Thread Local Storage structures in Windows NT, 2000 and XP to run virus code, and W32.Chthon, the first virus to run as a native application in Windows NT, 2000 and XP, Cupertino, Calif.-based Symantec said.
Reprinted with permission from
Story copyright 2009 International Data Group. All rights reserved.
Security
Additional Resources



White Papers & Webcasts
Death to PST Files
Download Now
The Tangled Web: Silent Threats & Invisible Enemies
Download Now
Tape Killed the IT Guy
Watch Now
Forrester Consulting Mobility Study: Taking Control of Enterprise Mobile Device Diversity
Download Now
BRM: What You Can Do To Reduce Risk In Challenging Times
Watch this webcast now!
What IT Must Do to Support Employee-Owned BlackBerry, iPhone and Android Mobile Devices
Download Now
Web 2.0, Social Media and the Dark Web - A Web Criminals Paradise?
In this discussion, learn about the challenges of protecting your users from the potentially unsafe content hidden in the "Dark Web".
eGuide: Enterprise Security
Smart Security Strategies for 2010. Read now!
Disaster Recovery 2008: Reduced Costs and Improved Performance
How long can your Enterprise afford to be without your data? With an accelerated disaster recovery program, you never have to answer this...

