Welcome!

Wearables Authors: Carmen Gonzalez, Liz McMillan, Yeshim Deniz, Elizabeth White, Christopher Harrold

News Feed Item

Spammers Target Mobile Users with More Than 350,000 Unique SMS Spam Variants in 2012

Cloudmark, Inc., the global leader in messaging threat protection for communication service providers, today unveiled new research demonstrating the sophisticated and varied methods used by attackers to target mobile users. Cloudmark’s comprehensive 2012 Messaging Threat Report revealed there were more than 350,000 unique unsolicited mobile spam variants in 2012, with the highest churn rate in December with more than 53,000 unique variants alone.

Spammers have favourite categories of attacks and frequently change individual messages in order to try and evade detection, resulting in a large number of variants. The report reveals that the most common unsolicited spam purported to be gift card offerings (44%), iPhone and iPad free giveaways (11%) and, in the UK in particular, Payment Protection Insurance (PPI) compensation (3%), which appeared after legislators determined that refunds were due to loan recipients who had been mis-sold the insurance.

The report findings are gathered through the Cloudmark-powered GSMA Spam Reporting Service, launched at Mobile World Congress in 2012. Mobile users can report their unsolicited spam by forwarding it to ‘7726’ spelling out SPAM on their keyboard. Suspicious texts submitted to this service help Cloudmark tackle spam on behalf of participating carriers, who receive comprehensive reports with detailed information on spam content, senders and reporters, which enables them to block numbers and reduce further spam.

Neil Cook, CTO at Cloudmark, said: “Global smartphone adoption rapidly increased in 2012, with smartphone users passing the 1 billion mark and this has consequentially resulted in a hike in mobile messaging spam. As opposed to email, we often automatically trust that our SMS must come from someone we know or have done business with and attackers are well aware of this wide acceptance, using it to their advantage. Our research is highlighting the growth of sophisticated mobile threats as new mobile technologies develop and 2013 will see a rise in this sophistication.”

The 2012 Messaging Threat Report identifies the top scam trends that will continue in 2013, such as the first Android botnet to be used to send SMS spam and the use of blended messaging threats to dupe mobile users.

SpamSoldier—Android Botnet Spreads SMS Spam

The SpamSoldier Android Botnet, initially seeded via SMS messages, purported to offer free versions of popular mobile games. Unknown to users, the downloaded game files contained both an initial loader program and a pirated copy of the game. When mobile users ran the game, the loader program sent SMS spam, deleted itself and installed the pirated game.

The sophistication of SpamSoldier was further highlighted as the loader simultaneously added a filter to block incoming SMS messages, preventing the user from being notified that they were spamming their contacts. During the period when the spam was first detected in November to when it was taken down in December, it is estimated that the spammer sent between five and ten million SMS messages, resulting in several thousand mobile devices being infected with the malware.

Blended Messaging Threats Bring New Level of Sophistication

Blended messaging threats also built momentum during 2012. These attacks used a combination of email, SMS messaging, instant messaging conversations and mining of social network relationships to send spam. With Affiliate Webcam Spam, for example, spammers start by sending out a sequence of SMS messages that to appear to be one half of an interactive conversation. Scammers then coax the mobile user into ‘conversing’, by sending predetermined questions or answers to the mobile user. From SMS, scammers then entice the user to converse on other platforms such as instant messenger to ultimately lead them to a webcam site which offers an affiliate program that pays $40 per sign up.

Free Offers Most Likely to Dupe Mobile Users

The 2012 Messaging Threat Report also identified the most popular method to dupe mobile users is by offering items for free. ‘Receive a gift card’ and having a ‘trial of an iPad or iPhone’ totaled more than 50 percent of the volume of SMS spam.

This type of ‘giveaway’ spam often requires the mobile user to offer privacy-compromising information via a survey and multiple click-throughs to various sites to qualify for the free ‘gift.’ Spammers are able to extract the user’s personal information to continue to push their scam campaign. Mobile users can qualify to receive the gift but often the costs associated with receiving the product outweigh the gift.

To avoid mobile users becoming victims of unsolicited SMS spam, Cloudmark is offering five tips:

  • Mobile users are strongly encouraged to forward spam texts to their carrier via “7726” spelling out “SPAM” on the keypad
  • Do not text “STOP.” This response only works with text alerts that the recipient has legitimately signed up to, and has the reverse effect for spam texts – merely confirming that the number is live and encouraging the spammer to continue to target that phone
  • Only download mobile applications from reputable app stores and read the terms of service closely
  • Never respond to an SMS requesting login details or other personal details – particularly if it claims to be a bank or financial institution
  • Speak to your mobile operator to see if you can set up content filters on your mobile account so that premium rate texts cannot be charged and adult content displayed.

Notes to Editors

For the complete Cloudmark 2012 Messaging Threat Report, please visit: http://www.cloudmark.com/releases/docs/threat_report/Cloudmark_2012_Annual_Threat_Report.pdf

About Cloudmark

Cloudmark builds messaging security software that protects communications service provider networks and their subscribers against the widest range of messaging threats. Only the Cloudmark Security Platform™ delivers instant security and control across diverse messaging environments, enabling communications service providers to create a safe user experience, protect revenue and safeguard their brand, while streamlining infrastructure and reducing operational costs. Cloudmark's patented solutions protect more than 120 tier-one customers worldwide, including AT&T, Verizon, Swisscom, Comcast, Cox and NTT. For more information, please visit www.cloudmark.com.

More Stories By Business Wire

Copyright © 2009 Business Wire. All rights reserved. Republication or redistribution of Business Wire content is expressly prohibited without the prior written consent of Business Wire. Business Wire shall not be liable for any errors or delays in the content, or for any actions taken in reliance thereon.

@ThingsExpo Stories
SYS-CON Events announced today that Interoute has been named “Bronze Sponsor” of SYS-CON's 20th International Cloud Expo®, which will take place on June 6-8, 2017, at the Javits Center in New York City, NY. Interoute is the owner operator of Europe's largest network and a global cloud services platform, which encompasses over 70,000 km of lit fiber, 15 data centers, 17 virtual data centers and 33 colocation centers, with connections to 195 additional partner data centers. Our full-service Unifie...
With major technology companies and startups seriously embracing Cloud strategies, now is the perfect time to attend @CloudExpo | @ThingsExpo, June 6-8, 2017, at the Javits Center in New York City, NY and October 31 - November 2, 2017, Santa Clara Convention Center, CA. Learn what is going on, contribute to the discussions, and ensure that your enterprise is on the right path to Digital Transformation.
SYS-CON Events announced today that Progress, a global leader in application development, has been named “Bronze Sponsor” of SYS-CON's 20th International Cloud Expo®, which will take place on June 6-8, 2017, at the Javits Center in New York City, NY. Enterprises today are rapidly adopting the cloud, while continuing to retain business-critical/sensitive data inside the firewall. This is creating two separate data silos – one inside the firewall and the other outside the firewall. Cloud ISVs ofte...
SYS-CON Events announced today that Hitachi Data Systems, a wholly owned subsidiary of Hitachi LTD., will exhibit at SYS-CON's 20th International Cloud Expo®, which will take place on June 6-8, 2017, at the Javits Center in New York City. Hitachi Data Systems (HDS) will be featuring the Hitachi Content Platform (HCP) portfolio. This is the industry’s only offering that allows organizations to bring together object storage, file sync and share, cloud storage gateways, and sophisticated search and...
SYS-CON Events announced today that delaPlex will exhibit at SYS-CON's @ThingsExpo, which will take place on June 6-8, 2017, at the Javits Center in New York City, NY. delaPlex pioneered Software Development as a Service (SDaaS), which provides scalable resources to build, test, and deploy software. It’s a fast and more reliable way to develop a new product or expand your in-house team.
Existing Big Data solutions are mainly focused on the discovery and analysis of data. The solutions are scalable and highly available but tedious when swapping in and swapping out occurs in disarray and thrashing takes place. The resolution for thrashing through machine learning algorithms and support nomenclature is through simple techniques. Organizations that have been collecting large customer data are increasingly seeing the need to use the data for swapping in and out and thrashing occurs ...
A strange thing is happening along the way to the Internet of Things, namely far too many devices to work with and manage. It has become clear that we'll need much higher efficiency user experiences that can allow us to more easily and scalably work with the thousands of devices that will soon be in each of our lives. Enter the conversational interface revolution, combining bots we can literally talk with, gesture to, and even direct with our thoughts, with embedded artificial intelligence, whic...
Detecting internal user threats in the Big Data eco-system is challenging and cumbersome. Many organizations monitor internal usage of the Big Data eco-system using a set of alerts. This is not a scalable process given the increase in the number of alerts with the accelerating growth in data volume and user base. Organizations are increasingly leveraging machine learning to monitor only those data elements that are sensitive and critical, autonomously establish monitoring policies, and to detect...
Internet of @ThingsExpo, taking place October 31 - November 2, 2017, at the Santa Clara Convention Center in Santa Clara, CA, is co-located with the 21st International Cloud Expo and will feature technical sessions from a rock star conference faculty and the leading industry players in the world. @ThingsExpo Silicon Valley Call for Papers is now open.
DevOps is often described as a combination of technology and culture. Without both, DevOps isn't complete. However, applying the culture to outdated technology is a recipe for disaster; as response times grow and connections between teams are delayed by technology, the culture will die. A Nutanix Enterprise Cloud has many benefits that provide the needed base for a true DevOps paradigm.
SYS-CON Events announced today that SoftLayer, an IBM Company, has been named “Gold Sponsor” of SYS-CON's 18th Cloud Expo, which will take place on June 7-9, 2016, at the Javits Center in New York, New York. SoftLayer, an IBM Company, provides cloud infrastructure as a service from a growing number of data centers and network points of presence around the world. SoftLayer’s customers range from Web startups to global enterprises.
In his keynote at @ThingsExpo, Chris Matthieu, Director of IoT Engineering at Citrix and co-founder and CTO of Octoblu, focused on building an IoT platform and company. He provided a behind-the-scenes look at Octoblu’s platform, business, and pivots along the way (including the Citrix acquisition of Octoblu).
SYS-CON Events announced today that DivvyCloud will exhibit at SYS-CON's 20th International Cloud Expo®, which will take place on June 6-8, 2017, at the Javits Center in New York City, NY. DivvyCloud software enables organizations to achieve their cloud computing goals by simplifying and automating security, compliance and cost optimization of public and private cloud infrastructure. Using DivvyCloud, customers can leverage programmatic Bots to identify and remediate common cloud problems in rea...
SYS-CON Events announced today that Tintri, Inc, a leading provider of enterprise cloud infrastructure, will exhibit at SYS-CON's 20th International Cloud Expo®, which will take place on June 6-8, 2017, at the Javits Center in New York City, NY. Tintri offers an enterprise cloud platform built with public cloud-like web services and RESTful APIs. Organizations use Tintri all-flash storage with scale-out and automation as a foundation for their own clouds – to build agile development environments...
SYS-CON Events announced today that Carbonite will exhibit at SYS-CON's 20th International Cloud Expo®, which will take place on June 6-8, 2017, at the Javits Center in New York City, NY. Carbonite protects your entire IT footprint with the right level of protection for each workload, ensuring lower costs and dependable solutions with DoubleTake and Evault.
SYS-CON Events announced today that Tappest will exhibit MooseFS at SYS-CON's 20th International Cloud Expo®, which will take place on June 6-8, 2017, at the Javits Center in New York City, NY. MooseFS is a breakthrough concept in the storage industry. It allows you to secure stored data with either duplication or erasure coding using any server. The newest – 4.0 version of the software enables users to maintain the redundancy level with even 50% less hard drive space required. The software func...
SYS-CON Events announced today that Technologic Systems Inc., an embedded systems solutions company, will exhibit at SYS-CON's @ThingsExpo, which will take place on June 6-8, 2017, at the Javits Center in New York City, NY. Technologic Systems is an embedded systems company with headquarters in Fountain Hills, Arizona. They have been in business for 32 years, helping more than 8,000 OEM customers and building over a hundred COTS products that have never been discontinued. Technologic Systems’ pr...
SYS-CON Events announced today that Cloudistics, an on-premises cloud computing company, has been named “Bronze Sponsor” of SYS-CON's 20th International Cloud Expo®, which will take place on June 6-8, 2017, at the Javits Center in New York City, NY. Cloudistics delivers a complete public cloud experience with composable on-premises infrastructures to medium and large enterprises. Its software-defined technology natively converges network, storage, compute, virtualization, and management into a ...
SYS-CON Events announced today that EARP will exhibit at SYS-CON's 20th International Cloud Expo®, which will take place on June 6-8, 2017, at the Javits Center in New York City, NY. "We are a software house, so we perfectly understand challenges that other software houses face in their projects. We can augment a team, that will work with the same standards and processes as our partners' internal teams. Our teams will deliver the same quality within the required time and budget just as our partn...
DevOps at Cloud Expo – being held October 31 - November 2, 2017, at the Santa Clara Convention Center in Santa Clara, CA – announces that its Call for Papers is open. Born out of proven success in agile development, cloud computing, and process automation, DevOps is a macro trend you cannot afford to miss. From showcase success stories from early adopters and web-scale businesses, DevOps is expanding to organizations of all sizes, including the world's largest enterprises – and delivering real r...