
The American company Dasient, which develop antivirus solutions for sites and advertising networks, found that the number of vulnerabilities in mobile android platforms over the past two years has doubled, according to Haker.ru .
During the study, the results of which will be presented at the Black Hat conference in Las Vegas next month, the company's experts analyzed 10 thousand applications to establish the level of infection and vulnerability before the attacks.
It was established that more than 800 transferred personal data to an unauthorized server. In addition, the researchers found that 11 applications send potentially undesirable SMS messages to other smartphones-which is, according to the technical director of Neil Daswani, a mobile version of Spam. Some of these applications send paid SMS messages when starting.
“Ultimately, the user pays for these messages, and they can be quite expensive,” the expert explains. This resembles the old fraud with the dialing for paid numbers when the infected computer called and called. ”
The study of Dasient, in addition, showed that mobile malware can spread through the so-called "passing" (drive-by) loading from legitimate applications when the computer is infected when visiting a website containing malicious code. Drive-by loading has already become the main method of distribution among the authors of harmful programs in the world of wireless devices.
The data obtained by the company confirm that malicious programs for mobile devices can be distributed through legitimate popular applications.
True, such downloads still usually leave a noticeable mark, for example, they often spoil the browser interface when stealing data from the device. In the future, the authors of mobile malware will find methods for deploying malicious programs without damage to the device, which will allow you to effectively hide the infection and steal data for a longer period of time without detection, predicts the Nile Daswani.
This kind of fraud, apparently, will continue until mobile providers and manufacturers of devices develop agreements regarding how to manage marketing and commercial SMS, predicts Daswani. In some cases, suppliers of legitimate applications simply initiate sending SMS messages without the consent of the user, since there are no rules requiring such consent yet, he noted.