Google Search

Showing posts with label 50000. Show all posts
Showing posts with label 50000. Show all posts

Monday, September 24, 2012

Android SMS malware firm fined £50,000 and ordered to refund victims

Over 170,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest security threats.

Hi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats.

Already using Google+? Find us on Google+ for the latest security news.

Mobile phone money. Image from ShutterstockBack in February, a SophosLabs researcher Vanja Svajcer discussed how he had discovered a malicious link on Facebook that led to malware being downloaded onto his Android smartphone.

Svajcer analysed the malware, adding detection for it as Andr/Opfake-C, and discovered that while posing as a conduit to popular games, it was coded to send an SMS message which subscribed the phone to an expensive premium rate service.

He even made a very short video of the malware automatically downloading to his Android phone.

(Enjoy this video? Check out more on the SophosLabs YouTube channel.)

Normally, the story stops there. We find malware, we stop malware. The end.

But this time, there's more to report.

Spurred by Naked Security's report of the malware, and complaints from the public, PhonepayPlus - the regulatory body for all premium rate phone-paid services in the United Kingdom - investigated who was hiding behind the phone numbers.

PhonepayPlus also confirmed the app's behaviour:

The Service, which was accessed via downloading an app (the "App"), enabled users to access popular games. Before installation of the App, consumers were presented with a screen titled "Downloader" (Appendix A). On selecting "install" the consumer was presented with a screen which stated, "Do you agree with the rules of downloading" and had two buttons, one marked “OK” and a second marked "Rules" (Appendix B).

Where a consumer selected "OK", a text message was sent to shortcode 80079, which prompted the Service to charge the user £10 by automatically sending a message from shortcode 79555 to the handset. Where a consumer selected "Rules", s/he was presented with eight pages of terms and conditions (Appendix C). Pricing information for UK users was located on the sixth page.

Consumers were given the opportunity to select buttons marked "Agree" or "Disagree". Where "Agree" was selected, a text message was sent to shortcode 80079, which prompted the Service to charge the user £10 by automatically sending a message from shortcode 79555 to the handset. The Executive took the view that consumers were not notified in advance of the charges.

After being charged, the consumer was redirected to the 7mobi.net "GamePortal", where s/he could play popular games.

Android app

PhonepayPlus discovered that the premium rate numbers used by the malware belonged to Moscow-based firm ??? ???????? (translated as Connect Ltd trading as SMSBill), and adjudicated that the company had made "very serious" breaches of the PhonepayPlus Code of Practice.

For one thing, the app's small print (hidden away on the 6th page of the terms and conditions) claimed that charges of "about 5 GBP" were applicable. And yet, the true charge was £10.

Anyone who did go to the effort of reading the T&Cs would not only be told that the fee was less than it actually was, but would also be assured that they would be notified before incurring any charges (they weren't).

PhonepayPlus said that the service provided by the Android app "had the sole purpose of generating high revenue and did so through recklessly misleading promotion and design."

Connect Ltd was also criticised for appearing "to have no regard to the Code and/or Guidance", and failure to co-operate with the investigation in a prompt or adequate manner.

In total, consumers are said to have spent some £100,000 - £250,000 on the service, although it is unclear how much revenue Connect Ltd themselves made.

Old phonePhonepayPlus has ordered Connect Ltd to pay a fine of £50,000 and refund - within three months - all consumers who used the service, whether or not they have claimed a refund.

Additionally, for the next two years Connect Ltd will have to receive prior permission from PhonepayPlus for any premium rate services it attempts to offer in the UK.

Some might wonder if Moscow-based Connect Ltd might be tempted to ignore the penalties imposed on it from the UK, but PhonepayPlus spokesman James McLarin was bullish.

McLarin told Naked Security that PhonepayPlus expects the fines to be paid and that the refund will take place:

"If our sanctions are not met we do have the power to bring a breach of sanction case, where the tribunal can impose tough penalties."

The sending of expensive SMS messages is one of the most common ways in which smartphone malware attempts to earn revenue from its victims.

Always be careful about what apps you install, and - in the case of Android apps - be sure to check that you are happy with the permissions the app requests at installation.

If you haven't already done so, you may consider installing Sophos's free anti-virus for Android to detect Opfake-C and other Android malware.

Follow @gcluley

Phone with money image from Shutterstock.


View the original article here

Saturday, June 2, 2012

Angry Birds malware - Firm fined £50,000 for profiting from fake Android apps

Over 170,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest security threats.

Hi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats.

Angry BirdsA firm has been fined £50,000 after Trojan versions of popular Android apps secretly sent expensive SMS messages to premium rate numbers.

UK industry regulator PhonepayPlus uncovered that 1,391 mobile phone numbers in the UK had been stung by the scam, that targeted Android owners who downloaded Trojan horse versions of popular games such as "Angry Birds", "Assassins Creed" and "Cut the Rope".

Each time innocent users would start one of the apps it would send three premium rate text messages, costing £15. Charges would continue to mount unless users removed the offending app.

Swift action by the authorities in shutting down the SMS shortcode used by the malware meant that only
£27,850 was taken, and funds were stopped from reaching the bogus app's developers.

But, according to PhonepayPlus, the scam wasn't just targeting smartphone users in Britain, but had also been seen in a total of 18 countries worldwide.

It's estimated that there were some 14,000 downloads of the malicious apps around the globe.

A1 Agregator Limited ran the premium rate payment system used by the malware to fraudulently charge consumers' smartphones.

A1 Agregator's website

As well as the firm being fined £50,000, it has also been ordered to directly refund all consumers within three months, regardless of whether they complained or not. In addition, the company has been barred from launching any other premium rate services in the UK without the permission of PhonepayPlus.

Android marketSophos experts have seen a rising trend for malware to be distributed in the form of bogus Android apps, hellbent on earning money from expensive SMS services or allowing the installation of further malicious code.

Recent examples have included false versions of Angry Birds Space, Instagram and even fake Android anti-virus products.

Earlier this year, PhonepayPlus fined two companies £100,000 each after they created typosquatting websites, posing as Twitter and Wikipedia, and tricked visitors into signing up for a premium rate mobile phone service.

It's good to see more action being taken against those who try to hit smartphone users where it hurts - in the pocket.

But this shouldn't just be about relying upon the authorities for protection.

For instance, be sure to check the permissions that an app requires when you install it on your Android. Does it have a legitimate reason to ask for them? If you don't see why it requires permission to send SMS messages, be cautious.

Logastrod permissions

You can further increase your chances of keeping your Android smartphone defended by installing Sophos's free anti-virus protection for Android.

Follow @gcluley

View the original article here