The United States Computer Emergency Response Team (US-CERT) has flagged the release of a free BlackBerry spyware application that allows an attacker to call a user's BlackBerry and listen to personal conversations.
The application, called PhoneSnoop, was publicly released as a proof-of-concept. It was first discussed at the Hack-in-the-Box security conference this year.
You install and run PhoneSnoop on a victims’ BlackBerry. PhoneSnoop sets up a PhoneListener and waits for an incoming call from a specific number. Once it detects a call from that specific number, it automatically answers the victims’ phone and puts the phone into SpeakerPhone mode. This way, the attacker that called can now hear what's going on at the victims end.
In order to install and setup the PhoneSnoop application, attackers must have physical access to the user's device or convince a user to install PhoneSnoop, US-CERT said.
The response team called on BlackBerry users to only download BlackBerry applications from trusted sources and to password protect and lock BlackBerry devices.