Access member only content, take part in discussions with comments on blogs, news and reviews and receive all the latest security industry news directly to your inbox. Join now for free.
Processing registration... Please wait.
This process can take up to a minute to complete.
A confirmation email has been sent to your email address - SUPPLIED EMAIL HERE. Please click on the link in the email to verify your email address. You need to verify your email before you can start posting.
If you do not receive your confirmation email within the next few minutes, it may be because the email has been captured by a junk mail filter. Please ensure you add the domain @scmagazine.com.au to your white-listed senders.
A botnet of infected Android phones has been discovered that pumps out pharmaceutical spam.
Microsoft engineer Terry Zink found the network operating across Asia, the former soviet states and South America.
Sophos researchers verified the botnet, which most likely infected users via less reputable Android app markets.
Google denied the botnet was based on Android devices.
Zink conceded the email headers may have been spoofed and the signature tagline "Yahoo Mail for Android" faked, but that was less likely than the existence of the droid bot.
Android botnets have been created by researchers in the past, but this was the first known instance of one network used for malicious purposes.
Zink said the Android phones had sent spam from a victim's Yahoo! email account
"We’ve all heard the rumours, but this is the first time I have seen it – a spammer has control of a botnet that lives on Android devices," Zink said.
"This ups the ante for spam filters. If people download malicious apps onto their phone that capture keystrokes for their email software, it makes it way easier for spammers to send abusive mail."
Sophos researcher Savio Lau spotted animated graphics within the spam emails, an inclusion that could lead to expensive phone bills.
"You can imagine the cellular phone bill you might receive if your phone is being used to download and spam out thousands of these messages," Sophos scribe Chester Wisniewski said.
Copyright © SC Magazine, Australia
To begin commenting right away, you can log in below or register an account if you don't yet have one. Please read our guidelines on commenting. Offending posts will be removed and your access may be suspended. Abusive or obscene language will not be tolerated. The comments below do not necessarily reflect the views or opinions of SC Magazine, Haymarket Media or its employees.