Select your language

Smartphone Malware Report

Smartphones, the new target of online fraud mafias
The low awareness of users and the large amount of personal and confidential information, the main motivations of the mafias for this new type of attackThe National Council of Consultants on CyberSecurity (CNCCS) provides you with a guide of good practices to protect your smartphoneThe study (PDF) aims to constitute an x-ray that reflects the current situation of smartphones in terms of s... Smartphones, the new target of online fraud mafias
The low awareness of users and the large amount of personal and confidential information, main motivations of the mafias for this new type of attackThe National Council of Consultants on CyberSecurity (CNCCS) provides you with a guide of good practices to protect your smartphoneThe study (PDF) aims to constitute an x-ray that reflects the current situation of smartphones in terms of security, describing the main threats they face, as well as existing measures to mitigate the associated risks. Mobile devices are no longer simple phones and cannot and should not be treated as such.

Mobile devices have evolved to converge practically in terms of functionalities with personal computers, a fact that translates into a notable increase in the usability of mobile phones in any field. But as a negative note we must highlight an increase in the risks that are associated with them.

The generalization of the offer of flat rates for smartphones has meant a totally vertiginous popularization of these devices, but the problem is that users are not aware of the dangers involved in not having their terminal protected or the amount of personal information that is stored in it. As a consequence of this, the existing mafias have expanded their horizons of action and have included this sector among their objectives. A goal of great growth and high remuneration.

The first malicious code intended for mobile devices appeared in 2004, but since then the attacks have evolved at a dizzying speed until reaching the last one detected a few months ago: ZEUS Man in the Mobile.

"For many years security companies have warned that mobile devices would be the target of most of the attacks that occur today in the PC world, and it was finally in 2010 where we saw the change in the trend. We believe that 2011 will really be the year where attacks on mobile devices will go from being an estimate, to being a reality," says David Barroso, director of S21sec e-crime.

- Publicidad -

You have to be prepared for future infections as malware creators continuously evolve their techniques and there is no doubt that malware for mobile devices will continue to evolve taking into account that the near future points to an incredible increase in smartphones for all types of operations: mobile as a means of payment, electronic banking, tracking individuals via mobile GPS, advanced social engineering attacks, etc.
"One of the big problems that security professionals have been facing is the mobility of users. Within this mobility, along with laptops, tablets and the like, smartphones are playing an increasingly decisive role. Increasing the security of these devices, from all their points of view -from malware to the protection of stored information, through their management or auditing- is a challenge for any security department, a challenge to face immediately if we want to protect our information and, therefore, our business "says Antonio Villalón, Director of Security of S2 Grupo.

How can users protect their devices?

Limited security awareness of users of these devices and consequent behavior may be the biggest risk factors for smartphones in the short term. It is of great importance to understand that a mobile device of these characteristics is no longer a simple phone and cannot and should not be treated as such.

The CNCCS proposes a series of good practices to help us protect our mobile devices:

Enable device access measures such as PIN or password if available. Configure the smartphone for automatic lock after a few minutes of inactivity. Before installing a new application check your reputation. Only install applications that come from trusted sources. Pay attention to the permissions requested by the applications and services to be installed. Keep the software updated, both the Operating System and the applications. Disable features while not in use: Bluetooth, infrared or Wi-fi.Set Bluetooth as hidden and password-required. Perform regular backups. Encrypt sensitive information when possible. Use encryption software for calls and SMS. Whenever possible do not store sensitive information on the smartphone, ensuring that it is not cached locally. When disposing of the smartphone erase all the information contained in the smartphone. In case of theft or loss of the smartphone inform the service provider by providing the IMEI of the device to proceed with its blocking. In certain cases, remote or automatic erase options may be used (after several failed access attempts). Monitor the use of resources on the smartphone to detect anomalies. Review invoices for possible fraudulent uses. Maintain an attitude of awareness in the correct use of these devices and the associated risks. Exercise extreme caution when opening an email, an SMS attachment or clicking on a link. It should be noted that this was one of the ways of entry of the Zeus-Mitmo.Distrust of files, links or numbers that come in unsolicited emails or SMS. Avoid using Wi-Fi networks that don't offer trust. Consider these types of devices in your corporate security policy. "While mobile threats are not yet part of the target of many cybercriminals, we are seeing the first real attacks by them appear. In the coming months, attacks for mobile devices, mainly for those based on Android, Google's operating system, will grow exponentially," says Luis Corrons, technical director of PandaLabs.

Source: National Council of Consultants on CyberSecurity (CNCCS)

See original.

No comments

• If you're already registered, please log in first. Your email will not be published.

Comments are closed

The comments for this content are closed.

Investing in Access Controllers: Why Eliminating Them Can Be a Strategic Mistake

Investing in Access Controllers: Why Eliminating Them Can Be a Strategic Mistake

Thanks to technological evolution, today there are smart readers with the capacity to process credentials, store information and even operate locks autonomously. This has led many organizations to...

Case study: How did a retail chain in Costa Rica reduce fraud by 18%?

Case study: How did a retail chain in Costa Rica reduce fraud by 18%?

Almacenes El Rey is a rapidly expanding department store, with 18 branches nationwide and more than one million customers each year. Thanks to the Avigilon Unity Video solution, the retail chain...

Is storing video no longer enough? Milestone's Sales Director for Latam speaks

Is storing video no longer enough? Milestone's Sales Director for Latam speaks

Latin America. Johana Arias, an executive at Milestone Systems, discusses how the integration of AI, natural language, and open platforms are transforming video into actionable insights for...

Anti-intrusion system described as one of Ajax's largest in South America

Anti-intrusion system described as one of Ajax's largest in South America

Argentina. The Bayron company installed a protection system with more than 85 Ajax wireless devices in the new branch of Autos del Sur S.A., Toyota's official dealership in the country.

Interview with Manuel Carlos, Senior Sales Director for Mexico at Hanwha Vision

Interview with Manuel Carlos, Senior Sales Director for Mexico at Hanwha Vision

Mexico. Manuel Carlos, an executive at Hanwha Vision, details how the company is revolutionizing electronic security by consolidating generative artificial intelligence and processing at the edge.

Prosegur presents new capabilities in cybersecurity and automation

Prosegur presents new capabilities in cybersecurity and automation

International. Prosegur Security has created two new modules, xCope and xEcute, which aim to provide companies and organizations with a new corporate digital surveillance service and another for...

Access and video platform

Access and video platform

Johnson Controls Designed to take the complexity out of legacy systems, the latest version of C•CURE IQ helps organizations achieve faster response, simplify workflows, and turn safety data into...

SIA presents the new directives of its International Relations Committee

SIA presents the new directives of its International Relations Committee

Latin America. Mariana Ramírez is the new president of the International Relations Committee of the Security Industry Association (SIA), while Vanesa Cabral assumed the role of vice president.

Access management and security in stadiums during the World Cup

Access management and security in stadiums during the World Cup

International. With the World Cup underway, stadium operation and the management of credentials and critical assets become key factors in ensuring security in high-demand environments.

Jovicard modernizes its headquarters with HID access control technology

Jovicard modernizes its headquarters with HID access control technology

Brazil. Jovicard, which specializes in physical access control, secure identity, biometrics and integrated electronic security, completed the modernization of its corporate headquarters with trusted...

Suscribase Gratis
Remember Me
SUBSCRIBE TO OUR ENGLISH NEWSLETTER
DO YOU NEED A SERVICE OR PRODUCT QUOTE?
LATEST INTERVIEWS
SITE SPONSORS










LATEST NEWSLETTER
Latest Newsletter