PDA Street

Home | News | Reviews | Features | FREE Downloads | Forums | Compare PDA Prices | Compare SmartPhone Prices


 WindowsMobileToday > News > F-Secure Names Smartphone Spyware Trojan

F-Secure Names Smartphone Spyware Trojan

By James Alan Miller
March 30, 2006

Click to View
The first program to secretly monitor calls and SMS messages on mobile handsets has anti-virus companies up in arms. Finland’s F-Secure even named FlexiSPY Light, from Thailand-based Vervata, a Symbian Trojan for S60 interface smartphones.

Common in the PC world, FlexiSPY is the first spyware application for handsets. Vervata plans to add support for Research In Motion's BlackBerry wireless handhelds and Microsoft-based Pocket PC Phones shortly.

Vervata describes FlexiSpy as a 'activity logger' for catching cheating spouses and monitoring children. It logs SMS messages, incoming and outgoing call history and durations, GPRS (data) activity, and contact information on a remote server for access later through a Web page. So not only does it raise questions about the ethical nature of spying, but there are concerns about the remote storage of personal information for people who don’t know their data is being remotely stored - let alone monitored - as well.

F-Secure is so concerned about FlexiSPY Light, the security vendor has designated the software SymbOS/Trojan-spy.Flexispy.A and added it to the definition file for its F-Secure Mobile Anti-Virus software. So if a phone is 'infected' the owner is told they’re being spied on.

Vervata takes issue with F-secure adding FlexiSPY to its anti-virus sofware, asserting in a statement to The Register that the Trojan label was not justified and users could remove the application themselves. The user in question is the one who put FlexiSPY on the phone in the first place and not the one unknowingly carrying it on their handset, of course.

"An uninstall option is provided for the user, so the application can be removed at any time. Configuration settings are also available to allow frequency of connections, thereby allowing the user to minimize network connections to once daily if required," according to Vervata.

Victims - those being spied on - have no idea the software is running on their handset. F-Secure's Jarno Niemela writes on the company's blog, "This application installs itself without any kind of indication as to what it is. And when it is installed on the phone it completely hides itself from the user."

The software has a hidden user interface that can only be accessed by the person who bought the $49.95 application and installed it on the phone.

To F-Secure, that's enough to make FlexiSPY malicious code. But what if the software got into the wrong hands? It could get worse, F-Secure says.

A creator of malicious code could install FlexiSPY as part of malware payload, for example. "Or a hacker could simply send it to a victim over Bluetooth and trust that there are enough curious people to install it," Niemela adds.

Vervata counters by pointing out that its software is incapable of spreading automatically. "FlexiSPY is activity monitoring software that needs to be consciously installed by a human, who knows exactly what the software does. It does not self replicate, it does not pretend to be something it is not, and it always requires conscious human action for installation," the company told The Register.

It adds, however, "Like any other monitoring software there may be a possibility for misuse, but there is nothing inherent in FlexiSPY that makes it illegal or malicious. F-Secure's comments categorising FlexiSPY as a Trojan are completely incorrect."

Nonetheless, as F-Secure points out - and even Vervata readily cautions on its Web site - spying on personal phone conversations is illegal in most countries throughout the world.

So when Vervata quotes a divorcee saying, "I finally figured out my wife was cheating on me with my brother. I had a bad feeling about this for over a year. After the divorce, my life is so much better now," you have to wonder exactly how many users would actually have the legal right to apply the software in that manner where they live. And how many already have?

A more advanced version of Vervata's spyware application for smartphones, FlexiSpy Pro, is in the works; adding support for MMS and e-mail to the capabilities of the light product. Vervata also plans to provide remote monitoring of actual phone conversations as they're happening.

Users who surreptitiously install FlexiSpy Pro will be able to specify a phone number from which they can call the smartphone without it ringing. The call activates the microphone on the phone, enabling them to act like a 'fly on the wall' during conversations.



Related Links:

  • J2ME Trojan Targets Mass Market Handsets
  • Update: Crossover Atypical Mobile, Desktop Trojan
  • Kaspersky Targets Mobile Malware
  • Smartphone Malware Masquerades as Antivirus Program
  • Symantec Secures Symbian Smartphone

     
     Printable Version
     Email this Story to a Friend  Add Your Opinion



    User Opinions:

    Total: 14 Opinions  -   Displaying: 3 of 14  Read More...


    CxEjaxCUQX
    yuKGRu uaaemtufsevu, [url=http://qcmlnkfsajor.com/]qcmlnkfsajor[/url], [link=http://lnrnavrvwztp.com/]lnrnavrvwztp[/link], http://pvvuzepwpgyn.com/...more

    Submitted by: 668.666666666667



    mhxjiddd
    hylfyjhr http://aibdnmds.com pdrparnq pgkijxeg lcrorvay [URL=http://xceuvdxs.com]ruflqfwd[/URL] ...more

    Submitted by: mhxjiddd



    EYWbkwxirjdPcPPABb
    better than one's word, south asian teens, [url="http://www.ahomeforless.com/mowiland/images/hot-moms.html"]south asian teens[/url], http://www.ahomeforless.com/mowiland/images/hot-moms.html south asian teens, tgrxd, facial gland anatomy, [url="http...more

    Submitted by: Andromache



     Add Your Opinion  See All 14 Opinions >>



  • PDA/Smartphone Newsletters
    text html text html
    X WindowsMobileToday X PDAStreet
    X Palm Boulevard X SmartPhoneToday
    X BlackBerryToday X Pocket PC Wire
    X iPhoneGuide      

    Other Personal Technology Newsletters
    X Sharky Extreme X WiFi Planet




    JupiterOnlineMedia

    internet.comearthweb.comDevx.commediabistro.comGraphics.com

    Search:

    Jupitermedia Corporation has two divisions: Jupiterimages and JupiterOnlineMedia

    Jupitermedia Corporate Info


    Legal Notices, Licensing, Reprints, & Permissions, Privacy Policy.

    Advertise | Newsletters | Tech Jobs | Shopping | E-mail Offers

    Solutions
    Whitepapers and eBooks
    Microsoft Article: Will Hyper-V Make VMware This Decade's Netscape?
    Microsoft Article: BitLocker Encryption on Windows Server 2008
    Go Parallel Article: Intel Thread Checker, Meet 20 Million LOC
    IBM Whitepaper: Innovative Collaboration to Advance Your Business
    Internet.com eBook: Real Life Rails
    Avaya Article: Call Control XML - Powerful, Standards-Based Call Control
    Tripwire Whitepaper: Seven Practical Steps to Mitigate Virtualization Security Risks
    Internet.com eBook: The Pros and Cons of Outsourcing
    Internet.com eBook: Best Practices for Developing a Web Site
    IBM CXO Whitepaper: The 2008 Global CEO Study "The Enterprise of the Future"
    Avaya Article: Call Control XML in Action - A CCXML Auto Attendant
    Go Parallel Article: James Reinders on the Intel Parallel Studio Beta Program
    IBM CXO Whitepaper: Unlocking the DNA of the Adaptable Workforce--The Global Human Capital Study 2008
    Adobe Acrobat Connect Pro: Web Conferencing and eLearning Whitepapers
    Go Parallel Article: Getting Started with TBB on Windows
    HP eBook: Storage Networking , Part 1
    MORE WHITEPAPERS, EBOOKS, AND ARTICLES
    Webcasts
    Go Parallel Video: Intel(R) Threading Building Blocks: A New Method for Threading in C++
    HP Video: Is Your Data Center Ready for a Real World Disaster?
    Microsoft Partner Portal Video: Microsoft Gold Certified Partners Build Successful Practices
    HP On Demand Webcast: Virtualization in Action
    Go Parallel Video: Performance and Threading Tools for Game Developers
    Rackspace Hosting Center: Customer Videos
    Intel vPro Developer Virtual Bootcamp
    HP Disaster-Proof Solutions eSeminar
    HP On Demand Webcast: Discover the Benefits of Virtualization
    MORE WEBCASTS, PODCASTS, AND VIDEOS
    Downloads and eKits
    Amyuni Download: PDF & XPS Engine for Your .NET and ActiveX Applications
    Microsoft Download: Silverlight 2 Software Development Kit Beta 2
    30-Day Trial: SPAMfighter Exchange Module
    Red Gate Download: SQL Toolbelt
    Iron Speed Designer Application Generator
    Microsoft Download: Silverlight 2 Beta 2 Runtime
    MORE DOWNLOADS, EKITS, AND FREE TRIALS
    Tutorials and Demos
    IBM IT Innovation Article: Green Servers Provide a Competitive Advantage
    Microsoft Article: Expression Web 2 for PHP Developers--Simplify Your PHP Applications
    MORE TUTORIALS, DEMOS AND STEP-BY-STEP GUIDES