WEF Attendees Warned about Mobile Security

Kaspersky Lab has warned attendees at the World Economic Forum in Davos about the risk of cyber-espionage attacks using malware designed for mobile devices. Many of the cyber-espionage groups investigated by Kaspersky Lab in recent years were found to make use of sophisticated mobile malware, capable of infecting a range of mobile devices and stealing all kinds of valuable information.

According to the company, significant events, like the World Economic Forum, serve as a hub for important conversations and attract high-profile visitors from all over the world. But a high concentration of important people in one place also attracts malicious cyber-attackers, who consider public events a good opportunity to gather intelligence with the help of targeted malware.

kaspersky

According to Kaspersky Lab statistics, at least five of the sophisticated cyber-espionage campaigns discovered in recent years have made use of malicious tools capable of infecting mobile devices. Sometimes these are custom-made malicious programs, created and propagated during a given cyberespionage campaign, as was seen in the Red October, Cloud Atlas and Sofacy campaigns.

In other cases, the malicious actors tend to use so-called commercial malware: a special set of offensive tools sold by commercial organisations like HackingTeam (whose tool is called RCS), Gamma International (FinSpy) and others.

The data stolen with help of such tools, such as competitive intelligence, is of immense value to cyber-spies. Many organisations believe that standard PGP encryption is sufficient to protect mobile email communications, but this is not always the case.

This measure doesn’t solve the core problem. From a technical perspective, the original architectural design used in emails allows for metadata to be read as plain text on both sent and received messages. This metadata includes details of the sender and the recipient as well as the sent/receipt date, subject, message size, whether there are attachments, and the email client used to send out the message, among other things, said Dmitry Bestuzhev, security expert at Global Research and Analysis Team, Kaspersky Lab.

To overcome this, many sensitive conversations now take place over mobile devices using secure applications and end-to-end encryption with almost no metadata or where metadata is basically impersonal.

However, there are additional measures that could help to protect private mobile communications from third party access. Dmitry Bestuzhev recommends the following:

  1. Always use a VPN connection to connect to the Internet. This helps to ensure that your network traffic cannot easily be intercepted and reduces its susceptibility to malware that can be been injected directly into a legitimate application being downloaded from the Internet.

  2. Do not charge your mobile devices using a USB port connected to a computer, as it could be infected with special malware installed on the PC. The best thing you can do is to plug your phone directly into the AC power adapter.

  1. Use a mobile anti-malware program. It has to be the best one. It seems that the future of these solutions lies precisely in the same technologies already implemented for desktop security: Default Deny and Whitelisting.

  2. Protect your devices with a password, not a PIN. If the PIN is found, the cyber-attackers may gain physical access to your mobile device and install the malware implant without your knowledge.

  3. Use encryption in the data storage memories that come with your mobile devices.

  4. Do NOT Jailbreak your device, especially if you’re not sure how it will impact your device.

Comment what you think!