Microsoft Engineer Discovers Android Spam Botnet, Google Denies Claim
An anonymous reader writes "Microsoft engineer Terry Zink has discovered Android devices are being used to send spam. He has identified an international Android botnet and outlined the details on his MSDN blog. A closer look at the e-mails' header information shows all the messages come from compromised Yahoo accounts. Furthermore, they are also stamped with the 'Sent from Yahoo! Mail on Android' signature. Google has denied the allegations. 'The evidence does not support the Android botnet claim,' a Google spokesperson said in a statement. 'Our analysis suggests that spammers are using infected computers and a fake mobile signature to try to bypass anti-spam mechanisms in the email platform they're using.'"
This seems like a much easier way to send spam... Most users will be using the stock mail app so just install, ask for the world in privileges (most users just click yes to anything), then send spam in the background using the user's account.
If you are smart, you avoid sending any spam to that user's contacts and intercept any replies that contain the spam text as a quoted string. That would make it far less likely for the victim to notice anytime soon.
Even if the spam isn't coming from Android phones right now, I'm sure someone will do it eventually.
Natural != (nontoxic || beneficial)
Fascinating conclusion he's come to. It looks like MS engineers don't understand Joe jobs.
"I've got more toys than Teruhisa Kitahara."
And if so does it match the generation scheme used by Android.
If it's a repeating "Message-ID: " as the blog suggests then it's likely forged.
I see emails from compromised accounts. The one thing that appears to be common is that it is always from Yahoo accounts. After one of my friends had her Yahoo account compromised, I throughly scanned her PC -- nothing showed up. I scanned the hard drive while connected to a known clean PC, so it wasn't just a well hidden malware.
I am beginning to wonder if there is a vulnerability in Yahoo's security that is being used to compromise accounts.
The real "Libtards" are the Libertarians!
That was largely my thought, Android devices lack the processing power and access to bandwidth that your average laptop or desktop has. While I'm sure it's technically possible to have an Android spam botnet, it really begs the question as to why anybody would bother to develop such a thing. Considering how unreliable the connects are and how little you can transmit combined with the increased difficulty of getting the code to run, it doesn't seem like something that would be profitable enough to justify making at this point.
FWIW, I see far more frivolous lawsuits from Apple these days than from Microsoft. In fact, when was the last time we talked about a Microsoft lawsuit?
It don't smell like a Joe Job to me, its smells like another Yahoo bug. Those that read one of my previous journal entries here knows that there was a bug that would let anyone surfing with FF who had a Yahoo account send spam thanks to a hidden iFrame, and frankly looking at my spam folder there is a LOT, I mean a hell of a lot, of spam both coming from Android and from regular but with ONE thing in common...Yahoo.
I have to wonder if the spammers haven't found a way to use the same bug they used on FF on Android, because yahoo's new layout seems especially weak to this form of attack it makes more sense that they are using a browser hack than having the entire Android system compromised but who knows? There are a hell of a lot of older Android versions out there, maybe they found a weakspot in the 2.x line and are hitting it.
But in the end somebody needs to be talking to the security guys at Yahoo and find out what they are using to hit their emails, be it a browser hack or something nastier.
ACs don't waste your time replying, your posts are never seen by me.