ie8 fix
madison

Zero Day

Ryan Naraine, Emil Protalinski and Dancho Danchev

New variants of premium rate SMS trojan 'RuFraud' detected in the wild

By | January 20, 2012, 12:07pm PST

Summary: Researchers from AegisLab, have intercepted several new variants of the infamous RuFraud premium rate SMS trojan.

Researchers from AegisLab, have intercepted several new variants of the infamous RuFraud premium rate SMS trojan.

How the infection takes place:

In order to earn money from the premium-rate SMS, the trojan will fake itself as a famous app, like Angry Birds; or downloader/installer of well-known softwares, it looks like ‘real thing’. Some of these kinds of apps appear on the third-party download sites, and some will repackage itself, post to the official Android Marketplace, and try to lure innocent people to install it.

The malicious attackers have bundled the premium rate SMS trojan into a fake copy of the popular app Angry Birds. Upon execution, the trojan seems permissions to sent SMS messages. Once the user confirms that the application is free to do so, the trojan will start sending premium rate SMS messages to multiple numbers outlined in AegisLab’s post.

Kick off your day with ZDNet's daily e-mail newsletter. It's the freshest tech news and opinion, served hot. Get it.

Dancho Danchev is an independent security consultant and cyber threats analyst, with extensive experience in open source intelligence gathering, malware and cybercrime incident response.

Disclosure

Dancho Danchev

More details on Dancho Danchev's current and past professional affiliations, can be found in his LinkedIn profile.

Biography

Dancho Danchev

Dancho Danchev is an independent security consultant and cyber threats analyst, with extensive experience in open source intelligence gathering, and cybercrime incident response. He's been an active security blogger since 2007, and maintains a popular security blog sharing real-time threats intelligence data with the rest of the community on a daily basis. More details on Dancho Danchev's current and past professional affiliations, can be found in his LinkedIn profile. You can also follow him on Twitter

Related Discussions on TechRepublic

Did you know you can take part in these discussions with your ZDNet membership?
6
Comments

Join the conversation!

Just In

RE: New variants of premium rate SMS trojan 'RuFraud' detected in the wild
Stephen-B Updated - 23rd Jan
@tonymcs@... your only safe bet is to use WP 7 phones, as they are te only ones safe from this virus.
"Once the user confirms..." UAC ?
Good thing WP7 protects the users from things like this. Crapple, and Gagged, crap OSs will allow this to harm users due to those OSs having crap for security, while WP 7 has much better security.
@Stephen-B Still trying to pass yourself off as a security expert, eh sonny?
'Fraid not, as usual.
@radleym you're still a troll. Why haven't you been banned?. You do not add anything constructive, just thr typical ABM rants an insults. Are you that jerk RickK?
0 Votes
+ -
ANDROID, ANDROID TROJAN, THIS IS ANDROID
tonymcs@... Updated - 22nd Jan
Just compensating for leaving Android out of the title.

Funny how WP7 and Apple always get mentioned if there are problems, but in this case, they don't have to worry, do they?
@tonymcs@... your only safe bet is to use WP 7 phones, as they are te only ones safe from this virus.

Join the conversation!

Formatting +
BB Codes - Note: HTML is not supported in forums
  • [b] Bold [/b]
  • [i] Italic [/i]
  • [u] Underline [/u]
  • [s] Strikethrough [/s]
  • [q] "Quote" [/q]
  • [ol][*] 1. Ordered List [/ol]
  • [ul][*] · Unordered List [/ul]
  • [pre] Preformat [/pre]
  • [quote] "Blockquote" [/quote]
ie8 fix
Click Here
ie8 fix

The best of ZDNet, delivered

ZDNet Newsletters

Get the best of ZDNet delivered straight to your inbox

Facebook Activity

White Papers, Webcasts, & Resources
ie8 fix
ie8 fix