12-17-2013 12:39 PM
A mobile botnet called MisoSMS is wreaking havoc on the Android platform, stealing personal SMS messages and exfiltrating them to attackers in China.
Researchers at FireEye lifted the curtain off the threat today, describing MisoSMS as "one of the largest advanced mobile botnets to date" and warning that it is being used in more than 60 spyware campaigns.
FireEye tracked the infections to Android devices in Korea and noted that the attackers are logging into command-and-controls in from Korea and mainland China, among other locations, to periodically read the stolen SMS messages.
Android BotnetFireEye's research team discovered a total of 64 mobile botnet campaigns in the MisoSMS malware family and a command-and-control that comprises more than 450 unique malicious e-mail accounts.
FireEye security content researchers Vinay Pidathala said MisoSMS infects Android systems by deploying a malicious Android app called "Google Vx" that masquerades as an Android settings app used for administrative tasks.
The app uses a bit of trickery to install and hide itself from the user. Once it's installed, the app secretly steals the user’s personal SMS messages and emails them to a webmail command-and-control.