"The report found the bulk of this Russian malware wasn't coming from lone individuals in basements, but well-oiled malware producing machines."
"The report found the bulk of this Russian malware wasn't coming from lone individuals in basements, but well-oiled malware producing machines."
SMS malware is a topic old as coal on the darknet, there is even a tutorial on the hidden wiki; what I'm curious about is where those apps are distributed, AFAIK google play deals with it (at least the obvious sms ones) pretty well. From what I hear people complaining often on HN, in the US carriers are tied with Google. Meanwhile here in Poland I rarely see a phone that has google apps out of the box (usually there is some crapware from the carrier, a shitty nav app instead of gmaps, and maybe a youtube app and that's it) and external appstores are unlocked by default - I can assume it's a similar situation in Russia and those malicious apps are distributed through some local app stores. Can somebody from Russia comment on that?
It's usually harmless, 'cheaper-feeling' versions of popular applications. The malware that's being downloaded here is closer to getting a user to download a game that's similar to something popular -- think 'Minecraft Tips and Tricks App'
I don't know where the servers are physically located, nor does it matter.
I've seen numerous reports of Google Play apps being served with malware / showing malware-triggering ads. So it's cat and mouse even with international stores.
All that said, as you mentioned in the other comment - the root of the problem are cell companies, if not for them, the premium sms problem wouldn't exist.
Vendors put crapware there too but not much.