ZeuS crimeware variant targets Symbian and BlackBerry users

ZeuS crimeware variant targets Symbian and BlackBerry users

Summary: A ZeuS crimeware variant known as ZeuS Mitmo, has began targeting the two-factor authentication solution offered by the Polish ING bank.

SHARE:
TOPICS: Mobility, Security, Wi-Fi
5

A ZeuS crimeware variant known as ZeuS Mitmo, has began targeting the two-factor authentication solution offered by the Polish ING bank.

UPDATE: Devices running Windows Mobile are also targeted.

The variant, currently targeting Symbian and BlackBerry users works as follows. Upon successful infection, the crimeware injects a legitimately looking field into the web page. The aim is to trick end users into giving out their mTANs, which stands for mobile transaction authentication numbers. Now that the gang has obtained access to their cell phone number, including the type of the device, a SMS is sent back to the victim with a link to a mobile application targeting either Symbian or BlackBerry devices.

See also:

According to the security researcher Piotr Konieczny, the reason why Apple's iPhone was excluded is due to the fact that Apple has more control over the Apple Store, compared to Symbian or RIM (Research in Motion).

These relatively sophisticated attempts on behalf of cybercriminals, wouldn't be possible to execute if the user didn't get infected in the first place.

As always, users are advised to use least privilege accounts, browse the web in isolated environment, and ensure their hosts are free of outdated 3rd party software, browser plugins or OS-specific flaws.

Topics: Mobility, Security, Wi-Fi

Dancho Danchev

About Dancho Danchev

Dancho Danchev is an independent security consultant and cyber threats analyst, with extensive experience in open source intelligence gathering, malware and cybercrime incident response.

Kick off your day with ZDNet's daily email newsletter. It's the freshest tech news and opinion, served hot. Get it.

Talkback

5 comments
Log in or register to join the discussion
  • What's this?...

    ...No Apple fanboiz on hand to beat there chests?
    Yam Digger
  • RE: ZeuS crimeware variant targets Symbian and BlackBerry users

    I think you mean "their chests".
    jmgdalton
    • RE: ZeuS crimeware variant targets Symbian and BlackBerry users

      @jmgdalton
      No I'm pretty sure "Yam Digger" meant them chests over there.
      jeverettk
  • And why is this people?

    Because all of these 'other' phones run junk Operating Systems and have no idea how to just focus on quality. They just slap stuff together and presto! We are now in the phone business! NOT! FAIL!
    james347
    • RE: ZeuS crimeware variant targets Symbian and BlackBerry users

      @james347

      Shut up, fool.
      Hallowed are the Ori