Incidents

Mobile malware and the Muscovites

Yesterday one of our employees was out for the evening. And naturally enough, used the metro. As you may know, the Moscow Metro is one of the busiest mass transit systems in the world, transporting approximately 9 million people a day.

With so many passengers, a number of whom now have smartphones, what are the chances of infection by Cabir or another virus for mobiles? Hard to tell exactly – all we do know is that while descending to the station, our employee detected an attempt by Cabir to infect her phone.

This is the third time she’s experienced this in two months. You may think that this is a low frequency. You may also wonder why an employee of Kaspersky Lab is walking around with a phone in ‘visible to all’ mode.

In my opinion, it shows that Cabir has already spread far and wide, in Moscow if not in other regions of Russia. OK, three times in two months, when compared to the daily attacks which PCs are subjected to, isn’t that high a frequency. And Cabir doesn’t, theoretically, pose that much of a danger.

But this case illustrates the way in which mobile malware is gathering momentum. I don’t want to think about what will happen when someone – and this will happen sooner, rather than later – releases a viable worm for mobiles which is written with the intention of doing serious damage. Seems like the Metro might become a very dangerous place for smartphone owners.

Mobile malware and the Muscovites

Your email address will not be published.

 

Reports

Andariel deploys DTrack and Maui ransomware

Earlier, the CISA published an alert related to a Stairwell report, “Maui Ransomware.” Our data should openly help solidify the attribution of the Maui ransomware incident to the Korean-speaking APT Andariel, also known as Silent Chollima and Stonefly.

APT trends report Q2 2022

This is our latest summary of advanced persistent threat (APT) activity, focusing on events that we observed during Q2 2022.

Subscribe to our weekly e-mails

The hottest research right in your inbox