Chinese firms accused of 'Sexy Space' Trojan

Summary: F-Secure has named three China-based companies as the creators of the "Sexy Space" Trojan, which was identified last week to have passed through the Symbian Foundation's digital signing process.

F-Secure has named three China-based companies as the creators of the "Sexy Space" Trojan, which was identified last week to have passed through the Symbian Foundation's digital signing process.

XiaMen Jinlonghuatian Technology, ShenZhen ChenGuangWuXian Technology and XinZhongLi TianJin cloaked the malware, also known as Yxe, and submitted it to the Foundation under its Express Signing program, the security vendor said Wednesday in a statement.

Developers are required to submit mobile applications to the Symbian Foundation for evaluation, before the applications are accepted and enabled for handsets running the Symbian operating system. The apps are first automatically scanned for viruses, after following random samples are submitted for human audit. Sexy Space had not been subjected to human scrutiny, Symbian's chief security technologist Craig Heath said last week.

F-Secure's senior security response manager, Chia Wing Fei, explained that the Trojan would have allowed attackers to simply send a link via text message to a malicious Web site, and prompt the mobile recipient to download the worm. Once the malware is installed, it sends similar text messages to all contacts listed on the phone.

"These messages are sent in your name and from your phone," said Chia. "It means you will pay for each SMS sent by the worm. A typical cost for a single text message might be 5 cents. If you have 500 contacts in your phone, an infection would cost you [$25]."

According to F-Secure, this is the first identified text message worm. The company added that while the problem is currently not widespread, to date, there has been a few confirmed reports in China and the Middle East.

All Symbian Series 60 third-edition phones by Nokia, LG and Samsung are potential targets of the malware, including popular models such as Nokia N95 and Nokia E71, said F-Secure. The Symbian platform is used in just under 50 percent of all smartphones.

This article was originally posted on ZDNet Asia.

Topics: China, Malware, Security

Kick off your day with ZDNet's daily email newsletter. It's the freshest tech news and opinion, served hot. Get it.

Talkback

5 comments
Log in or register to join the discussion
  • I hope they are banned for life along with every employee at their company.

    That should send a message. It pisses me off to no end when i find out a company created a trojan/worm/virus.. i just want to see their heads bashed in to compensate for their stupidity.

    I know .. its violent and probably doesnt fit the crime of stupidity.. but come on guys.. stop trying to steal! I cant stand people who try to make money on false pretenses.
    Been_Done_Before
    • Actually...

      ... if the companies are physically in China, and if this causes the Chinese government any embarrassment, I wouldn't be surprised if there really were some executions handed out.
      Hallowed are the Ori
  • RE: Chinese firms accused of 'Sexy Space' Trojan

    Wow!

    Now we have another way to get screwed by cell phone carriers! Do you think any of them will remove charges for a worm that sends spam from your phone? NOT LIKELY!
    Rob.sharp
  • RE: Chinese firms accused of 'Sexy Space' Trojan

    I do have to blame Symbian first and XiaMen Jinlonghuatian Technology, ShenZhen ChenGuangWuXian Technology and XinZhongLi TianJin next for shared responsibility ... fines should be given to those offenders and customers who have been attacked should get apologies. It is time to create an accountability law and start prossecuting.
    Yves D Poulin
  • RE: Chinese firms accused of 'Sexy Space' Trojan

    Software security becomes all the more important with portable digital assistants like
    the iPhone. But I feel it is essential to keep a hard, off-line copy of materials that
    matter the most, and if need be, store sensitive digital data in an isolated, regulated
    environment where human error can take the minimum toll.
    hidefusa.okabe@...