Article 4TF61 Researchers unearth malware that siphoned SMS texts out of telco’s network

Researchers unearth malware that siphoned SMS texts out of telco’s network

by
Dan Goodin
from Ars Technica - All content on (#4TF61)
sms-800x534.jpg

Enlarge (credit: Eric Rice)

Nation-sponsored hackers have a new tool to drain telecom providers of huge amounts of SMS messages at scale, researchers said.

Dubbed "Messagetap" by researchers from the Mandiant division of security firm FireEye, the recently discovered malware infects Linux servers that route SMS messages through a telecom's network. Once in place, Messagetap monitors the network for messages containing either a preset list of phone or IMSI numbers or a preset list of keywords.

Messages that meet the criteria are then XOR encoded and saved for harvesting later. FireEye said it found the malware infecting an undisclosed telecom provider. The company researchers said the malware is loaded by an installation script but didn't otherwise explain how infections take place.

Read 5 remaining paragraphs | Comments

index?i=JCxIbz1rco0:BI3gxUaYTB0:V_sGLiPB index?i=JCxIbz1rco0:BI3gxUaYTB0:F7zBnMyn index?d=qj6IDK7rITs index?d=yIl2AUoC8zA
External Content
Source RSS or Atom Feed
Feed Location http://feeds.arstechnica.com/arstechnica/index
Feed Title Ars Technica - All content
Feed Link https://arstechnica.com/
Reply 0 comments