Return of the Yxe worm
Full article309 words · extracted from securelist.com · click to collapse
Just over a year ago Worm.SymbOS.Yxe appeared – this was the first malicious program for smartphones running Symbian S60 3rd edition which had a valid digital signature. From time to time subsequent versions of this worm appeared – the latest variant, Yxe.d was detected in July 2009.
Today we detected a new variant, Worm.SymbOS.Yxe.e, which also has a valid digital signature. Previous modifications of the worm:
- Spread via SMS messages which contained a link to the worm
- Used social engineering in order to trick victims
- Harvested data about the smartphone from the device
- Sent the harvested data to a cybercriminal server
- Attempted to terminate third party applications designed for working with the smartphone’s file system or with active applications.
The latest modification does all of the above and more. It also:
- Sends MMS messages containing a link to itself, and, attached, a black and white skull and crossbones image (Skuller, a Trojan which first appeared in 2004, also used a skull and crossbones)
- Connects to a Chinese social networking site
- Downloads files
- Block the smartphone’s Software Manager, making it more difficult to delete the malware
We’re still analysing Worm.SymbOS.Yxe.e in detail – we’ll keep you posted.
Latest Webinars
Reports
Kaspersky researchers have discovered new Mirage Kitten attacks using previously undocumented malware families: NodeRabbit in Node.js and PollCat in JavaScript.
Our experts discovered a new CoolClient backdoor variant with a kernel-mode rootkit driver that hides malicious processes, files, and network connections from security tools and threat analysts.
Kaspersky experts break down a new Armored Likho campaign that poses as a fundraising efforts and delivers a new Still Toolkit aimed at stealing Telegram data and eavesdropping on victims.
Kaspersky researchers reveal previously undocumented malware attributed to Mirage Kitten (UNC1549, Smoke Sandstorm, Nimbus Manticore): NightLedger backdoor, ArcBridge, and BridgeHead tunneling tools.
Text extracted automatically; images, tables and formatting may be missing. Original: https://securelist.com/return-of-the-yxe-worm/30614/