This site uses cookies. By continuing to browse the site you are agreeing to our use of cookies.  > Find out more here

 

All the latest UK technology news, reviews and analysis

Google lashes out at Microsoft's Android botnet allegations

by Alastair Stevenson

06 Jul 2012

View Comments

  • Tweet this
Google Android Malware

Google has lashed out at Microsoft researcher Terry Zink, claiming there is no evidence to support his warning that a new botnet is forcing infected Android phones to churn out spam.

The search giant said that its own internal research indicated the spam messages were stemming from PCs as opposed to smartphones in a statement sent to V3 on Friday.

"Our analysis suggests that spammers are using infected computers and a fake mobile signature to try to bypass anti-spam mechanisms in the email platform they're using," said Google.

The Android botnet reports initially stemmed from Microsoft researcher Terry Zink on 3 July, when he claimed to have discovered evidence that a botnet had successfully infiltrated the Android ecosystem.

In his post Zink warned that a new form of the malware was accessing Yahoo Mail accounts on Android devices to send spam messages.

He also reported tracking the originating IP addresses to Asia, Eastern Europe, South America and the Middle East.

If true the botnet would be the first ever discovered successfully targeting the Android ecosystem.

Since Google's attack Zink has issued a second blog post admitting the spam headers could have been spoofed to make it look like they came from Android devices instead of a PC.

"Yes, it's entirely possible that bot on a compromised PC connected to Yahoo Mail, inserted the message-ID thus overriding Yahoo's own Message-IDs and added the 'Yahoo Mail for Android' tagline at the bottom of the message all in an elaborate deception to make it look like the spam was coming from Android devices," wrote Zink.

"The other possibility is that Android malware has become much more prevalent and because of its ubiquity, there is sufficient motivation for spammers to abuse the platform. The reason these messages appear to come from Android devices is because they did come from Android devices."

Other security vendors have also reported finding evidence that the spam stemmed from Android.

Initially Sophos issued its own report verifying that it too had discovered evidence of a botnet running on infected Android smartphones.

Lookout chief technology officer Kevin Mahaffey suggested that rather than malware on the Android devices, a more likely explanation was the behaviour was attributable to Yahoo's Android email app.

"We’ve reached out to Yahoo with this information and they have acknowledged that their mobile team is actively working on these issues," Lookout said in a company blog.

The news follows on from warnings by security firm Trend Micro that cyber criminals are flocking to the Android ecosystem.

Do you agree

blog comments powered by Disqus

Poll

Business security poll

How concerned are you by the rising tide of cyber threats?

16%

56%

10%

9%

9%

Popular Threads

Powered by Disqus
Sony Xperia Z vs Apple iPhone 5

Sony Xperia Z vs Apple iPhone 5 head to head video review

V3 pits Sony's rugged flagship against Apple's premier handset

Updating your subscription status Loading

Connect with V3.co.uk

Sign up to our daily or weekly newsletters

newsletter sign-up button

mcafee

7 requirements for hybrid web delivery

It's no longer one or other with web security; you can now have a virtualisation and SaaS hybrid model

navisite

BYOD: the implications for the IT team

BYOD is important for employee satisfaction, but poses challenges in terms of security, productivity loss and costs

Network and Security Solutions Engineer

Network and Security Solutions Engineer Location: Caerphilly...

Lead Customer Support Engineer - world class tech start-up - London

Lead Customer Support Engineer - Mobile Applications...

Application Packaging Specialist - London

Software Systems Specialist - London The job holder...

Senior Software Engineer - World class Tech startup - London

Senior Software Engineer – Cloud platform (enterprise...

Keep up to date with the latest products, services and technologies from the world's leading IT companies. IThound.com brings you over 2,000 white papers, case studies and analyst reports.

To send to more than one email address, simply separate each address with a comma.