Trojan Steals Credit Card Numbers

http://www.schneier.com/blog/archives/2011/01/trojan_steals_c.html
via Byline

It’s only a proof of concept, but it’s scary nonetheless. It’s a Trojan for Android phones that looks for credit-card numbers, either typed or spoken, and relays them back to its controller.

Software released for Android devices has to request permissions for each system function it accesses—with apps commonly requesting access to the network, phone call functionality, internal and external storage devices, and miscellaneous hardware functions such as the backlight, LED, or microphone. These requests are grouped into categories and presented to the user at the point of installation—helping to minimise the chance of a Trojan slipping by.

Soundminer takes a novel approach to these restrictions, by only requesting access to ‘Phone calls,’ to read phone state and identity, ‘Your personal information,’ to read contact data, and ‘Hardware controls’ to record audio—none of which will ring alarm bells if the app is marketed as a voice recording tool.

Research paper here. YouTube . Another blog post. Research paper; section 7.2 describes some defenses, but I’m not really impressed by any of them.

fulltext?d=2mJPEYqXBVI fulltext?d=7Q72WNTAKBA fulltext?d=dnMXMwOfBR0

Advertisement

About Joe Woods
I have over 20 years experience in the Information Technology (IT) and Information Security arena. My involvement ranges from providing awareness all the way through to helping design, build and maintain secure services operated by large multinational organizations. Using the experience I have gained, my goal is to help everyone interact with technology and the internet in a way that protects them from harm. Here are some of the areas I have covered in those 20 years: Risk Management and Information Security, IT Security, Ethical Hacking, Networking, Firewalls, Web Servers (Apache and IIS), UNIX (Solaris and AIX), Linux (Red Hat), Windows Server, Intrusion Detection and Prevention systems, Web Site Design and Development

Leave a Reply

Fill in your details below or click an icon to log in:

WordPress.com Logo

You are commenting using your WordPress.com account. Log Out / Change )

Twitter picture

You are commenting using your Twitter account. Log Out / Change )

Facebook photo

You are commenting using your Facebook account. Log Out / Change )

Connecting to %s

Follow

Get every new post delivered to your Inbox.