F-Secure: Commwarrior claims first big victim

By Tom Espiner, Special to ZDNet Asia
Thursday, September 01, 2005 11:44 AM

The first serious outbreak of a mobile-phone virus in a company has been detected, according to security specialist F-Secure.

F-Secure security expert Patrick Runald said Tuesday that an outbreak of the Commwarrior.B virus occured at an unnamed Scandinavian company last Wednesday.

"This is the first time a mobile virus has infected an organization," Runald said. "It's a particularly nasty version of Commwarrior, as it just doesn't give up."

Commwarrior targets mobile phones that use the Symbian Series 60 operating system, and the bug spreads using Bluetooth and multimedia messaging technology, or MMS.

There are a few variants of the bug. With Commwarrior.A, an infected phone will spend the period between 8 a.m. and midnight attempting to spread the infection to other phones. Between 7 a.m. and 8 a.m, it attempts to delete evidence of its activity.

Commwarrior.B, on the other hand, "will continuously try to send itself for 23 hours out of 24," Runald said. "It's nastier than CommWarrior.A."

One of the employees at the company in question apparently received Commwarrior.B via, and then activated it by opening the program. "The virus then sent itself to every address in the address book; it was opened by more employees, who activated it, and it spread," Runald said.

Warnings that the messages did not come from a secure source were apparently ignored by employees.

"Fortunately, this did not affect the operation of the company," Runald said. The operator at the company disabled MMS temporarily, and Bluetooth was also disabled, which prevented the spread of the virus. The phones were then disinfected.

Runald recommended this approach to any other company that becomes infected.


WORTHWHILE?

0

0 votes
Blog

Talkback 0 comments

There are currently no comments for this post.


Tech Jobs Now!

Search for your ideal tech job:

Employ smoke tests at the start of your testing process

Web Development

The most basic tests any software developer must run are smoke tests, which are a set of written, non-exhaustive tests that only deal with the most functional aspects of a software application or process.


Read more »



What will social analytics say about your company?

Blog thumbnail

I was finally able to set aside some time the other night to reassess my privacy settings in Facebook, following changes made to the social network's privacy policy in December...... by Eileen Yu

Read more »

Tags

  1. attack
  2. authentication and encryption
  3. blog
  4. data security
  5. e - mail
  6. google inc.
  7. internet
  8. malware
  9. microsoft corp.
  10. microsoft windows
  11. network
  12. network security
  13. pc security
  14. researcher
  15. security
  16. security management
  17. software
  18. spam and phishing
  19. viruses and worms
  20. web