Cybercrime Supplement: Mobile Market April 2013 Mobile Threats and the Underground Marketplace Principal Investigators and Correspondent Authors Jart Armin & Andrey Komarov Contributing Researchers Mila Parkour, Raoul Chiesa, Bryn Thompson, Will Rogofsky Panel & Review Dr. Ray Genoe (UCD), Robert McArdle (Trend Micro),Dave Piscitello (ICANN), Foy Shiver (APWG), Edgardo Montes de Oca (Montimage), Peter Cassidy (APWG) APWG Mobile Fraud web site http://ecrimeresearch.org/wirelessdevice/Fraud/ Table of Contents Introduction 2 Underground cybercrime services 2 Pay by Install – Fake Mobile Browsers 3 1) Opera Mini 3 2) Fake social network applications 5 3) Fake Skype apps 6 Subscription Services 8 1) ZipWap.ru 8 2) Load‐WAP 9 3) StimulPremium 12 4) Supporting Infrastructures 13 Mobile Banking Malware 15 1) Flooders (Skype, ICQ SMS) 15 2) SMS Stealers 18 3) SMS Spam/Spoofing 21 4) Mobile Intrusion 24 Smishing & Phishing 27 Bulletproof Hosting Providers 28 Published April 25, 2013 ISBN # 978‐0‐9836249‐9‐8 Disclaimer: PLEASE NOTE: The APWG and its cooperating investigators, researchers, and service providers have provided this study as a public service, based upon aggregated professional experience and personal opinion. We offer no warranty as to the completeness, accuracy, or pertinence of these data and recommendations with respect to any particular company’s operations, or with respect to any particular form of criminal attack. This report contains the research and opinions of the authors. Please see the APWG web site – apwg.org – for more information. 1 An APWG Industry Advisory http://www.apwg.org ●
[email protected] PMB 246, 405 Waltham Street, Lexington MA USA 02421 Cybercrime Supplement: Mobile Market April 2013 Introduction Underground cybercrime services A thriving underground economy exists in the mobile market where cybercriminals adapt tried and tested techniques, used to exploit PC users, as well as a growing number of innovative techniques developed specifically for the rapidly expanding portable device arena.