Zeus Malware Turns To Smite BlackBerry Users

Mobile versions of the Zeus malware have been spotted targeting BlackBerry users in earnest, with four different samples discovered by security firm Kaspersky Labs.

Although this is not the first time BlackBerry owners have been targeted by Zeus, it is rare for them to be targeted by any threats at all, due to the quality of their security in comparison to other phones.

Given the declining popularity of the RIM devices, the findings were even more surprising, as hackers tend to go for the most used operating systems in mobile attacks, hence why Android is such a big target.

The first time Zeus was seen targeting RIM was back in 2010, TechWeekEurope was told by Kaspersky Lab expert Denis Maslennikov.

Doubling up

Fresh versions of ZitMo, or ZeuS-in-the-Mobile, were seen targeting BlackBerry and Android users across Europe, attempting to steal users’ banking data and their money, although the UK users appear to be free from harm.

ZitMo gets hold of banking information by intercepting all text messages and passing them on to attackers’ own devices. It gets onto devices inside malicious applications, which users are duped into downloading. In this case, the malicious app was posing as security software called ‘Zertifikat’.

Kaspersky found mobile users in Spain, Italy and Germany were targeted by these fresh variants, with two command and control (C&C) numbers found on Sweden’s Tele2 operator.

“The analysis of new Blackberry ZitMo files showed that there are no major changes. Virus writers finally fixed grammar mistake in the ‘App Instaled [sic] OK’’ phrase, which is sent via SMS to C&C cell phone number when smartphone has been infected,” Maslennikov said in a blog post.

“Instead of ‘BLOCK ON’’ or ‘BLOCK OFF’’ commands (blocking or unblocking all incoming and outgoing calls) now there are ‘BLOCK’’ and ‘UNBLOCK’’ commands. Other commands which are received via SMS remain the same.”

Earlier this year, Kaspersky warned of a set of malicious Android applications posing as security software. Zeus was sitting behind those apps, ready to siphon off text messages.

Are you a security guru? Try our quiz!

Thomas Brewster

Tom Brewster is TechWeek Europe's Security Correspondent. He has also been named BT Information Security Journalist of the Year in 2012 and 2013.

Recent Posts

Northvolt Mulls US Bankruptcy Protection – Report

Troubled battery maker Northvolt reportedly considers Chapter 11 bankruptcy protection in the United States as…

22 hours ago

FTC Plans Investigation Into Microsoft Cloud Business – Report

Microsoft's cloud business practices are reportedly facing a potential anti-competitive investigation by the FTC

1 day ago

Programmer Sentenced To Five Years In Prison For Bitcoin Laundering

Ilya Lichtenstein sentenced to five years in prison for hacking into a virtual currency exchange…

1 day ago

Hate Speech Watchdog CCDH To Quit Musk’s X

Target for Elon Musk's lawsuit, hate speech watchdog CCDH, announces its decision to quit X…

2 days ago

Meta Fined €798m Over Alleged Facebook Marketplace Violations

Antitrust penalty. European Commission fines Meta a hefty €798m ($843m) for tying Facebook Marketplace to…

2 days ago

Elon Musk Rebuked By Italian President Over Migration Tweets

Elon Musk continues to provoke the ire of various leaders around the world with his…

2 days ago