Russia's Massive Android Malware Industry Revealed
securitywatch.pcmag.com
securitywatch.pcmag.com
Those are used for fradulent services in like 95% cases. But, operators get as much as 50% share, so why bother getting rid of scammers?
I seriously want to see top managers of Russian cell operators in jail.
=> I seriously want to see top managers of every cell operator out there in jail.
FTFY
It's not a Russian problem, google for premium sms and you'll find international tables for countries all around the world. I've heard some providers give clients the option to disable premium sms, too bad it's not a sane default. Also, don't know how it is in the US, but around here premium sms are very popular among live tv shows - vote for your favorite dancer, etc. So it's a hard case to beat when mass media is tied with them.
- Refund your money
- Disable everything "premium" (fradulent) forever for your account.
- Legit mobile payments still pass, you will wonder! Just not those evil invisible recurrent account-draining ones.
In short, they understand that their multi-billion-dollar business is a bitch for low scammers and they live with it.
They are in business of defrauding children, elderly and vulnerable people who have better things to do than be careful and track their balance.
People got hang at Nuremberg for less I would say.
No.
There were people at Nuremberg who richly deserved hanging and didn't get it. The allies went easy on their best new buddy in the impending cold-war. ( Edit to say what motivated this reply in the first place - You can't compare working people to death in camps with SMS fraud. not anyplace close )
So you go and hack people's PBXes or phones or whatever and call these numbers non-stop and profit handsomely. Careless telecom (VoIP) providers are also good targets, as the updating of these prices is a haphazard operation.
It even happens inside the US. Some local telco (like in Iowa) gets a 7 cent rate published, then puts up free conference calls or whatever to generate traffic.
"SMS shortcodes that bill victims via their wireless carrier. In the U.S., we often see these attached..."
versus
"Readers in the U.S. can rest easy, since most of these scams use specific short codes that won't work outside Russia"
So, which one is it?
That's how Eurovision voting works for example.
But the whole code story is completely irrelevant! If malware is installed in your Android phone it can send any arbitrary short code it wants, without you noticing. What is important is the number to which you send the code, and this is different for each country (and even different for different carriers in some countries).
So, a well coded malware with international support would need to know the premium payment number + code pairs for all the countries the attacker wishes to gather money from.
The second one is letting the reader know that they do not need to be wary of every smartcode they see.
If malware is installed on your phone, you do not get to see the code (unless you have Android 4.2, which is only about 6% of the phones).
The point is not to install the apps. from unknown sources, even if they look like a well known application.
I'm not suggesting that there are no potential threats, what I'm suggesting is that they often omit the caveats and mitigating factors such as that the official Play Store doesn't host malware and even if something slipped in it wouldn't survive for long. The main concern would be about sideloaded apps and even then devices with Google Play Services installed (most of them) can still scan them: http://www.androidpolice.com/2013/07/28/googles-malware-scan...
Also Android 4.2 introduced premium SMS protection:
More control of premium SMS - Android will provide a notification if an application attempts to send SMS to a short code that uses premium services which might cause additional charges. The user can choose whether to allow the application to send the message or block it.
https://source.android.com/devices/tech/security/enhancement...
not in Russia (see the other comment sub-thread here https://news.ycombinator.com/item?id=6149405).
Of course the usual caveats apply to this kind of thing, but the presence of malware isn't interesting — the way it's being done is.
"The report found the bulk of this Russian malware wasn't coming from lone individuals in basements, but well-oiled malware producing machines."
SMS malware is a topic old as coal on the darknet, there is even a tutorial on the hidden wiki; what I'm curious about is where those apps are distributed, AFAIK google play deals with it (at least the obvious sms ones) pretty well. From what I hear people complaining often on HN, in the US carriers are tied with Google. Meanwhile here in Poland I rarely see a phone that has google apps out of the box (usually there is some crapware from the carrier, a shitty nav app instead of gmaps, and maybe a youtube app and that's it) and external appstores are unlocked by default - I can assume it's a similar situation in Russia and those malicious apps are distributed through some local app stores. Can somebody from Russia comment on that?
It's usually harmless, 'cheaper-feeling' versions of popular applications. The malware that's being downloaded here is closer to getting a user to download a game that's similar to something popular -- think 'Minecraft Tips and Tricks App'
I've seen numerous reports of Google Play apps being served with malware / showing malware-triggering ads. So it's cat and mouse even with international stores.
All that said, as you mentioned in the other comment - the root of the problem are cell companies, if not for them, the premium sms problem wouldn't exist.
I don't know where the servers are physically located, nor does it matter.
Vendors put crapware there too but not much.