ZeroHour
Kaspersky Securelistpublished ()ingested @Securelist

Strangers on a train

highMalwareimportance 42
Full article357 words · extracted from securelist.com · click to collapse

Incidents

Incidents

10 May 2007

minute read

We’re always warning users to be wary of files sent via Bluetooth from unknown sources. And this is why I was so surprised during a train trip the other day – I saw first hand evidence of how trusting people are when it comes to their mobiles.

A woman sitting in front of me took a call on her smartphone. A few minutes later a man who she clearly didn’t know asked if he could have her ‘cool ringtone’. She agreed, but for some reason he couldn’t persuade his smartphone to get the file via Bluetooth. Finally he asked her to give him her phone so he could copy the file directly from the memory card. She agreed without hesitating, handed over her smartphone…he copied what he needed to copy, handed the phone back, and left the compartment.

It’s possible that I’m suffering from an excess of occupational paranoia, and that the man really was interested only in the ringtone. I can’t be sure. However, I can be sure that he had access to all the data the woman had saved, not to mention the opportunity to copy malicious programs onto her phone. Maybe I am overly paranoid – but as long as I see people continuing to be so casual about phone security, I’ll keep telling them what they’re doing wrong.

As for the woman, she didn’t just get my ideas on security – she’ll be getting a free virus scanner for her smartphone too.

Latest Webinars
Reports

Kaspersky researchers have discovered new Mirage Kitten attacks using previously undocumented malware families: NodeRabbit in Node.js and PollCat in JavaScript.

Our experts discovered a new CoolClient backdoor variant with a kernel-mode rootkit driver that hides malicious processes, files, and network connections from security tools and threat analysts.

Kaspersky experts break down a new Armored Likho campaign that poses as a fundraising efforts and delivers a new Still Toolkit aimed at stealing Telegram data and eavesdropping on victims.

Kaspersky researchers reveal previously undocumented malware attributed to Mirage Kitten (UNC1549, Smoke Sandstorm, Nimbus Manticore): NightLedger backdoor, ArcBridge, and BridgeHead tunneling tools.

Text extracted automatically; images, tables and formatting may be missing. Original: https://securelist.com/strangers-on-a-train/30327/