Cell phone virus tries leaping to PCs

By Dawn Kawamoto, CNET News.com
Friday, September 23, 2005 11:13 AM

A Trojan virus that attempts to spread from smart phones to users' PCs was discovered Wednesday, marking one of the first cases of virus "cross-sharing" between the two devices, according to security firm F-Secure.

Cardtrap.A, a Trojan that attacks Symbian mobile phone operating systems, attempts to infect users' PCs if they insert the phone's memory card into their computers. Though this latest threat is considered low-level because it requires user interaction and fails to launch on a number of Windows systems, including XP, it may be a precursor to more sophisticated viruses designed for transfer between mobile devices and PCs, said Mikko Hypponen, F-Secure chief research officer.

"We expect to see more of this on the mobile front," Hypponen said. "We may begin to see Windows viruses spreading to PDAs that are synched up to computers, or go from PCs to mobile phones with the memory card."

Cardtrap.A copies two worms, Win32/Padobot.Z and Win32/Rays, to a phone's memory card. Once that card is inserted into the PC, Padobot.Z will attempt to start automatically on Windows-based machines via the autorun.inf file. The Ray worm, meanwhile, will create a bogus system folder on the user's desktop. Clicking on the folder unleashes a worm into the user's computer system.

The Ray worm is more likely than Padobot.Z to take root in a system, because the Padobot worm may only launch on older versions of Windows, or be restricted to just a few memory card readers.

Windows does not generally support auto-run from a memory card, which means that a virus won't automatically be transferred from a memory card to a user's PC and then launched. But in some instances, memory cards appear to the PC as CD-ROM drives, which would trick the auto-run feature into running the file, Hypponen said.

The volume of mobile-device malicious software has been rising rapidly, with 83 different viruses emerging within just a 14-month period, he added. Among the threats were the Fontal.A Trojan horse in April, the CommWarrior Trojan and the infamous Cabir virus.


WORTHWHILE?

0

0 votes
Blog

Talkback 0 comments

There are currently no comments for this post.


Tech Jobs Now!

Search for your ideal tech job:

A look at the Terminal Services Manager in Windows Server 2008

Windows Server

Terminal Services Manager has been around for a while, but Microsoft made some changes to the utility in Windows Server 2008. Here's what you'll find.


Read more »



Open source blog reloaded!

Blog thumbnail

This is with great pleasure that this "little corner of the Web" is resuming activities through another member of the (now famous ;-)) Beijing Linux User Group (BLUG) doing the..... by Fred Muller

Read more »

Tags

  1. attack
  2. authentication and encryption
  3. blog
  4. data security
  5. e - mail
  6. google inc.
  7. internet
  8. malware
  9. microsoft corp.
  10. network
  11. network security
  12. pc security
  13. researcher
  14. security
  15. security management
  16. software
  17. spam and phishing
  18. symantec corp.
  19. viruses and worms
  20. web