SC247    Topics     Technology    Security    Lookout

Cyber Attacks Targeting Smartphone Supply Chains

A new mobile trojan dubbed “DeathRing” is being pre-loaded on to smartphones somewhere in the supply chain, warn researchers at mobile security firm Lookout.


DeathRing is a Trojan believed to be of Chinese origin that masquerades as a ringtone app, but can download SMS and browser content from its command and control server to the victim’s phone.

DeathRing could use SMS content to phish a victim’s personal information, for example, using fake text messages requesting the data. 

The malware could also use browser content to prompt victims to download further Android application packages (APKs), which may include more malware.

Lookout researchers say the malicious app is impossible to remove because it is pre-installed in the system directory.

This is of concern to original equipment makers (OEMs) and retailers because the compromise of mobiles in the supply chain could have a significant impact on customer loyalty and trust in the brand.

Mainly affecting lower-tier smartphones bought in Asian and African countries, this is the second significant example of pre-installed mobile malware that Lookout has found on phones in 2014.

Download Report

The devices pre-loaded with DeathRing are so far mostly from third-tier manufacturers. The main countries affected are Vietnam, Indonesia, India, Nigeria, Taiwan and China.

Researchers said this signals a potential shift in cyber-criminal strategy towards distributing mobile malware through the supply chain.

Earlier this year, Lookout detected another pre-loaded piece of malware called Mouabad. Like DeathRing, Mouabad was also pre-installed somewhere in the supply chain and affected predominantly Asian countries, but researchers did see some cases in Spain.

Although it is impossible to remove DeathRing and Mouabad because they are pre-installed in the phone’s system directory, Lookout researchers recommend that mobile users:

  • Be aware of the origins of the device they are buying.
  • Download a mobile security app to protect against malware.
  • Check phone accounts regular for any unusual charges.


Source: ComputerWeekly

Related: Regin, a New Computer Spying Bug Discovered


Article Topics


Lookout News & Resources

Mobile Threats, Made to Measure
Cyber Attacks Targeting Smartphone Supply Chains

Latest in Technology

Happy Returns Partners With Shein and Forever 21 to Simplify Returns
Frictionless Videocast: AI and Digital Supply Chains with SAP’s Darcy MacClaren
The Top 10 Risks Facing Supply Chain Professionals
Walmart’s Latest Service: Ultra Late-Night Delivery
South Korea Finally Overtakes China in Goods Exported to U.S.
SAP Unveils New AI-Driven Supply Chain Innovations
U.S. Manufacturing is Growing but Employment Not Keeping Pace
More Technology

When we first got started, smartphones barely existed– now there are more than a billion shipped each year and hundreds of millions in our enterprises. Before everything and everyone went mobile, we knew it was going to change computing forever. And today we live in a world with billions of connected devices and we need someone to protect it. That’s Lookout.


View Lookout company profile

 

Featured Downloads

Unified Control System - Intelligent Warehouse Orchestration
Unified Control System - Intelligent Warehouse Orchestration
Download this whitepaper to learn Unified Control System (UCS), designed to orchestrate automated and human workflows across the warehouse, enabling automation technologies...
An Inside Look at Dropshipping
An Inside Look at Dropshipping
Korber Supply Chain’s introduction to the world of dropshipping. While dropshipping is not for every retailer or distributor, it does provide...

C3 Solutions Major Trends for Yard and Dock Management in 2024
C3 Solutions Major Trends for Yard and Dock Management in 2024
What trends you should be focusing on in 2024 depends on how far you are on your yard and dock management journey. This...
Packsize on Demand Packing Solution for Furniture and Cabinetry Manufacturers
Packsize on Demand Packing Solution for Furniture and Cabinetry Manufacturers
In this industry guide, we’ll share some of the challenges manufacturers face and how a Right-Sized Packaging On Demand® solution can...
Streamline Operations with Composable Commerce
Streamline Operations with Composable Commerce
Revamp warehouse operations with composable commerce. Say goodbye to legacy systems and hello to modernization.