BBC shows just how easy it is to create malicious apps for smartphones.
In a recent experiment by the BBC a crude game for a smartphone was cobbled together from freely available code snippets. Using more chunks of code downloaded from the web, inexperienced software writers were able to ensure their 'game' spied on anyone who downloaded it to their smartphone.
In the BBC's example all of the information-stealing elements of the spyware program were legitimate functions used elsewhere by legitimate programmes. However the authors used these functions for illicit purposes. Using standard code in this way makes malicious applications hard to spot, because genuine programs will use exactly the same functions.
Jason Dibley, Technical Director of London-based data security experts QCC Interscan acknowledges the difficulty of policing this additional threat. "Organisations need to understand how telephones are now being used for data storage and delivery by their staff," he says.
On the Blackberry and Ipod shops there are thousands of tools which are being downloaded to help workplace productivity. These include apps for Customer Relationship Management, expense tracking, business accommodation booking, spreadsheets, word processing, website updating, customer research, business news, weather reports, traffic reports and many many more.
It is too easy for a programmer to insert code in these apps which takes information off the phone and delivers it to an interested party. In recent weeks both Apple and Google have had to take a numbers of applications down from their respective online shops over concerns that those apps contained malicious code.
In many organisations the threat from these malicious apps is exacerbated by an age gap within the organisation itself.
Mr Dibley points out that "Some senior managers know that 'smartphones' exist, but still rarely use their own for anything except traditional calls and the odd text message. Meanwhile their younger and more tech-savy colleagues have completely changed their working practices, and are storing lots of business critical data on their blackberries, I-phones and other devices. They download loads of code to help them work more quickly and productively, but in doing so, expose their business to potential data theft."
Incident Response - Act Now
Act now if you suspect that you are under surveillance.
1. Cease all sensitive communications.
2. Remove yourself from the target area
3. Call QCC Interscan from a payphone on +44 0207 205 2100
Technical Surveillance Counter Measures (TSCM)
Providers of world class TSCM (bug sweeping) services Globally. We offer professional and effective counter surveillance
to keep vour valuable information safe from prying eyes.
Read
more...
High Net Worth Individuals
As a high level company executive, celebrity or high net
worth individual, your privacy is important. Our specialist services include TSCM (bug sweeping) services,
covering residential sites and executive vehicles. We can conduct security inspections and review
services for ocean going yachts, private planes, and executive motor
vehicles.
Read more...
Specialist Vehicle Search
As part of our security inspection service for high profile company executives and high net worth individuals, we offer an extended security inspection service for executive vehicles. This includes all types of yachts, executive cars, limousines and private executive jets.
We have completed increasing numbers of counter surveillance inspections
and physical security reviews globally of numerous marine vessels, executive
jets and company vehicles.
Read more...
Physical Security Review
This service inspects and reports on all aspects of physical security including
locks, access control, CCTV, waste management, executive transportation and
asset protection. The physical security review will also cover particular
areas clients direct our attention to.
Read more...
Tiger Testing Services
Tiger Testing is a special type of vulnerability test that originated in the United States Air Force who use it to test air base defences.
Commercial Tiger Tests are beneficial to companies and organisations to highlight
true physical, procedural or technical vulnerability and are especially useful
in the maintenance of particularly valuable assets.
Read more...
GSM Telephone Evaluation
QCC Interscan has a dedicated telephone forensics unit offering an exclusive service to clients who are worried that their personal mobile telephones are being secretly monitored.
Many spy shops and on line surveillance equipment suppliers offer software
packages that monitor mobile telephone conversations and text messages by
an unauthorised agent. These phone bugging software packages are very difficult
to detect without specialist equipment and knowledge.
Read more...
Installing permanent bug detectors
QCC Interscan now offers a complete solution to large clients with the highest level anti-bugging requirements.
If your organisation requires a higher level of security than that afforded
by regular manual TSCM sweeps, then talk to us about our newly developed systems
for 'permanent, always-on radio and GSM bug detectors.'
Read more...
High profile sports organisations
High profile sports organisations and venues are known targets for illicit surveillance. Boardrooms, changing rooms, executive suites and other areas are all vulnerable when big money is at stake.
Read more...






