A Microsoft researcher speculates that a new spam botnet may have originated from an illegitimate, third-party marketplace for Android apps.
endif; ?>Analysis of spam samples suggests that a malicious application could be using Android devices to spread spam messages, in what Microsoft researcher Terry Zink has called “the next evolution in the cat-and-mouse game that is email security.”
The spam messages share two similarities, Zink, who discovered the botnet, explained in a blog post. First, each message closes with the signature “Sent from Yahoo! Mail on Android.” Secondly, they all share a message ID that reads:
Message-ID:
Zink believes the botnet was created by a malicious app most likely found in an insecure market. After analyzing the IP addresses that were stamped in the headers of the messages, a routine practice of Yahoo Mail, Zink found that the IPs connected to servers in Chile, Indonesia, Lebanon, Oman, Philippines, Russia, Saudi Arabia, Thailand, Ukraine, and Venezuela.
RELATED: Researchers reveal new rootkit threat to Android security
Network World survey: Readers sound off on smartphone preferences
Because downloading a malicious app from the Android Market is highly unlikely, Zink says the fact that the messages stem largely from developing countries where Android’s app community has yet to establish an ecosystem indicates that the devices were infected by an illegitimate app downloaded elsewhere, Zink wrote:
I’ve written in the past that Android has the most malware compared to other smartphone platforms, but your odds of downloading and installing a malicious Android app is pretty low if you get it from the Android Marketplace. But if you get it from some guy in a back alley on the Internet, the odds go way up…
…I am betting that the users of those phones downloaded some malicious Android app in order to avoid paying for a legitimate version and they got more than they bargained for. Either that or they acquired a rogue Yahoo Mail app.
Neil Roiter, research director or Corero Network Security, said in an interview with InformationWeek that, if Zink’s theory is correct, this attack would be the first real-world evidence that shows the dangers of downloading Android apps from sources other than those approved by Google.
Furthermore, this approach could successfully evade webmail providers’ anti-spam efforts, Zink says.
“This ups the ante for spam filters. If people download malicious apps onto their phone that capture keystrokes for their email software, it makes it way easier for spammers to send abusive mail.”
UPDATE
Yahoo has commented on the issue, declaring that if there is an issue, it’s not with their app.
While our investigation into claims of a potential malware compromise operating as a botnet is ongoing, we can confirm that there is not a problem with our official Yahoo! Mail app for Android and there is no reason for users to uninstall the app. As one of the largest Web mail services in the world, we value our users’ privacy and safety and have taken efforts across our mobile offerings, including the Yahoo! Mail app for Android, to use information in an authorized manner and according to our privacy policies. We encourage users to only install mobile apps from authorized marketplaces and also to change their passwords on a periodic basis. Yahoo! Mail also encourages consumers to educate themselves with online safety tips at security.yahoo.com.




