Mariposa Botnet Malware Found On Vodafone HTC Magic
A pretty ballsy attack here. We’ve long been afraid of backdoors being added to vendor source code – be that OS or Firmware; in the form of an environmental variable, secret user accounts or even the more subtle route of intentional “bugs”. But a standard botnet worm spreading to PCs through phones “right out of the box”? Not very subtle as we can see from how quickly this was discovered and analyzed. Seems like just another vector for the Spanish botnet recently shut down and reported on in HNNCast. The real news here is that unlike P2P, USB and HTML links, THIS vector demonstrates the compromise of Vodafone deep enough inside to actually alter shipping product. What we DON’T know yet is whether this is related to a recent Vodafone website compromise, an unrelated Internet compromise, a physical break-in, an attacker getting “the right job” or what. We think this will become an interesting story as the details get filled in.
Following Energizer’s acknowledgment last week that it had been distributing infected software in conjunction with its DUO USB charger comes a report that malware has been found on a Vodafone HTC Magic running Google’s Android OS.
The malware in question includes code to create a Mariposa bot, the Conficker worm, and a trojan software designed to steal passwords from the game Lineage.
via Mariposa Botnet Malware Found On Vodaphone HTC Magic — InformationWeek.
Leave a Reply
You must be logged in to post a comment.










