On mySimon: Python 426P 460HP Security System
BNET Business Network:
BNET
TechRepublic
ZDNet

November 10th, 2009

Source code for ikee iPhone worm in the wild

Posted by Dancho Danchev @ 7:31 am

Categories: Apple, Botnets, Hackers, Malware, Viruses and Worms, iPhone

Tags: Apple iPhone, Worm, Cyberthreats, Smart Phones, Viruses And Worms, Security, Consumer Electronics, Personal Technology, Dancho Danchev

Following last week’s systematic exploitation of jailbroken iPhones in the Netherlands through a technique originally discussed in 2008, a 21 years old opportunist has recently launched the first iPhone worm, this time targeting customers of Australian mobile carriers.

Upon successful exploitation of devices running SSH with default passwords, the worm would announce its presence by changing the wallpaper to a new one featuring pop-star Rick Astley.

Despite the author’s intention to raise awareness on the issue, the originally released as “closed source” code for the “awareness-building worm” has now leaked in the wild, with several modifications already capable of stealing a compromised iPhone’s contacts and SMS messages.

In an interview published with the author of the iPhone worm, he states that his iPhone alone has already infected 100+ devices, and commented that international propagation “would have been sheer luck“, since “the code itself is set to firstly scan the 3G IP range the phone is on, then Optus/Vodafone/Telstra’s IP Ranges (I think the reason Optus got hit so hard is because the other 2 are NAT’d) then a random 20 IP ranges. I’m guessing a few phones hit a range that another vulnerable phone was on”.

Interestingly, in a recent poll results, 76% of the people who voted believe that “He’s done iPhone users a favour. This was an acceptable way to raise awareness of poor security“. I wonder what would their attitude be if they knew that several modifications and customized modules are already capable of stealing their SMS messages and contacts, potentially using them for fraudulent activities.

What do you think, did the teenagers that launched these attacks during the last two weeks did someone a favor, or did they actually started a short-lived trend with malicious copycats already looking for ways to exploit the potentially hundreds of thousands of jailbroken devices using the easy to find 3G IP ranges?

TalkBack.

Dancho DanchevDancho Danchev is an independent security consultant and cyber threats analyst, with extensive experience in open source intelligence gathering, malware and cybercrime incident response. He's been an active security blogger since 2007, and maintains a popular security blog. See his full profile and disclosure of his industry affiliations.

Email Dancho Danchev

Subscribe to Zero Day via Email alerts or RSS.

  • Talkback
  • Most Recent of 21 Talkback(s)
Even if so
There's still no need to leave it turned on. And
with the default password to boot! (Read the rest)
Posted by: AzuMao Posted on: 11/15/09 You are currently: a Guest | | Terms of Use
iPhone is officially the most malware ridden mobile platform in the world  NonZealot | 11/10/09
Far from defending Apple...  s_southern | 11/10/09
The need to jailbreak is inextricably linked to this, though...  bhartman36 | 11/10/09
What need?  oncall | 11/10/09
BZZZZT, wrong.  AzuMao | 11/10/09
You forgot...  Ceridan | 11/10/09
Actually  oncall | 11/10/09
But then..  Ceridan | 11/10/09
most people  athynz | 11/10/09
See my post above  oncall | 11/10/09
Dear MSZealot  HerbertH_02 | 11/10/09
Latching onto a lie once again  athynz | 11/10/09
EPIC fail.  AzuMao | 11/10/09
Oh come on...  athynz | 11/10/09
If you're doing it to switch carriers..  AzuMao | 11/11/09
You are misinformed  athynz | 11/14/09
Even if so  AzuMao | 11/15/09
What happened to the Droid?  7stringdude | 11/10/09
Sorry my bad  7stringdude | 11/10/09
RE: Source code for ikee iPhone worm in the wild  XArt | 11/10/09
And that  athynz | 11/10/09

What do you think?

SponsoredWhite Papers, Webcasts, and Downloads

advertisement

Recent Entries

advertisement

Archives

Favorite Links

ZDNet Blogs

White Papers, Webcasts, and Downloads

SmartPlanet

  • Thought-provoking progressive ideas on diverse topics that intersect with technology, business, and life, and matter to the world at large. Visit SmartPlanet
  • More from IBM
  • Innovate your business' process model, play against the market, compete against others on our scoreboards and WIN! Try INNOV8 2.0: A BPM Simulator
  • Enabling Real-World Business Transformation through IBM Service Management Read the EMA Analyst Report
Click Here