What makes Symbian malware tick

Jarno Niemelä F-Secure

  download slides (PDF)

Predicting future malware on a new platform is difficult. Thus it is not surprising, that most of the Symbian malware that we have seen so far is rather different than originally expected. The AV community was expecting binary malware doing basically the same things as on the PC platform. What we got was things that play with SIS installation files and other properties of the Symbian operating system.

In this paper the author covers the technical background of current Symbian malware and classifying new cases – when is something a new malware and when is it just another form or repackage of known malware?

On many points the Symbian OS is quite different from mainstream operating systems, so it is natural that some of the techniques used by Symbian malware are different than one might expect.

This paper gives an introduction to the Symbian operating system from the malware point of view. Covering the technical background on the OS features used by malware, what is their original intention, and how they are used for malicious purposes.

In addition, this paper covers classification of Symbian malware samples, what properties of a new malware sample need to be considered when deciding whether it is a new variant or not.


Poll

Who in your company is responsible for installing software patches?
System administrators
End users
I don't know

Leave a comment

Jobs Recruit Sidebar

Virus Bulletin

In this month's magazine:
  • Welcome to 2009
  • Anti-unpacker tricks – part two
  • A day in the life of an average user
  • Advancing malware techniques 2008
  • VB2009 Geneva: call for papers
  • MicroWorld eScan Internet Security Suite 10
  • Introducing VB anti-spam testing
Virus Bulletin 01 2009
Subscribe now!
Virus Bulletin currently has 148,292 registered users.