Showing posts with label BlackBerry. Show all posts
Showing posts with label BlackBerry. Show all posts

Tuesday, 12 April 2011

GCHQ says BlackBerry is safest

Mobile
BlackBerrys are the only recommended smartphones for handling highly sensitive Government data, according to a GCHQ division.

The UK's National Technical Authority for Information Assurance at GCHQ (CESG) has published smartphone security guidance for public sector workers.

The advice published today covers various phones, including the Apple iPhone, Windows Phone 7 devices, Nokia hardware and BlackBerrys.

Four security procedures documents have been produced, outlining how to best secure any mobile deployment for UK Government departments and organisations on those platforms.

“These security procedures cover architectural issues (such as recommended network layout, recommendations for operational monitoring), configuration advice, user education and training suggestions, and information on residual risks that senior risk owners will need to take into account,” a CESG spokesperson told IT PRO.

“The publication of this risk management advice and guidance is intended to ensure all UK Government organisations have access to the information they need to take educated risk management decisions when deploying remote working solutions using smartphones.”

CESG worked with the telecoms industry to produce the report on how to secure smartphones for remote working, covering lower risk situations.

The guidance document itself was not available to the press.

CESG claimed the document will help many parts of the public sector work more efficiently and effectively, in turn saving money for the taxpayer.

As for more handling serious data, however, the GCHQ body said the only way was BlackBerry.
“The BlackBerry Enterprise Solution from Research In Motion remains the only smartphone system to have been formally evaluated by CESG and is approved to protect material classified up to and including ‘restricted,’” CESG said.

RIM was unsurprisingly buoyant about that particular comment, as a host of supporters talked about BlackBerry security credentials.

“The BlackBerry platform remains, in my opinion, the leader in this respect, providing the highest levels of assurance without the added cost or complexity of needing to bring third-party software into the equation,” said Nick McQuire, director for enterprise mobility at analyst house IDC.

BlackBerry devices are not infallible of course, as the recent Pwn2Own contest highlighted when a Torch 9800 was successfully hacked.

“The reality is that BlackBerry does have more enterprise features and controls such as remote kill, email retention, guaranteed message deliver with application and encryption controls,” said Ron Gula, chief executive (CEO) of Tenable Network Security.

“However, while this is important, a lot of it is just details, and we'll probably see some leapfrogging between the various mobile vendors as they get bitten and react.”

[ITPro]

Friday, 4 March 2011

ZeuS Targets Mobile Users

As early as 2006, Trend Micro already recognized the fact that the BlackBerry technology could be exploited by cybercriminals. The smartphone may have remained spared from malware attacks over the years although there have been recent news of a ZeuS variant specifically targeting BlackBerry users. As we have said in a recent post, banking Trojans are evolving and more sophisticated attacks involving smartphones are among the most recent developments.

The ZeuS malware specifically targeting the BlackBerry OS is currently detected by Trend Micro as BBOS_ZITMO.B. Just like its desktop counterpart, this ZeuS variant does not display any graphical user interface (GUI) that can prompt users about the infection. Instead, it removes itself from the list of applications, in order to effectively stay under the radar.
Upon successful installation, it sends a confirmation message to the administrator to signal that it is ready to receive commands. It specifically sends the message “App Installed OK” to the U.K. number +447{BLOCKED} as seen in the screenshot below.
Click for larger view

BBOS_ZITMO.B also allows the attacker to remotely change the number to which it forwards SMS messages sent to the affected phone, also known as the administrator number. Thus, in the event that the original administrator number is tracked down and becomes unavailable, the attacker can just send a command to change the administrator number and continue receiving the forwarded messages.

Based on our analysis, BBOS_ZITMO.B is capable of carrying out the following commands:
  • Display SMS: Unmonitored SMS will be treated as a normal SMS and will be displayed on the phone.
  • Delete/Drop SMS: SMS from hacker will not be seen by the user.
  • Forward SMS: Send SMS to hacker without the user’s knowledge.
  • Block Calls
  • Remove Block Calls
  • Set Administrator: Register a new administrator.
  • On/Off
  • Add Sender
  • Remove Sender
  • Set Sender
  • Block/Unblock Phone Numbers
Other smartphone OSs are not immune to this threat either. Variants targeting smartphones running Symbian (SYMBOS_ZBOT.B) and Windows Mobile (WINCE_ZBOT.B) have also been spotted with behaviors that are very similar to those exhibited by BBOS_ZITMO.B.

With the increased popularity of mobile banking goes the increase of mobile threats. Thus users are strongly advised to keep their mobile devices secure, and be cautious in installing applications and clicking links sent by unknown users, as they may lead to the download of malicious applications.

[TrendMicro]