
Photo: Gustavo Ortiz / ISH
Pamela Carrasco / ISH
November 20th, 2013 (ISH) Smartphones have become so common they are the preferred target for cyber-criminals in Latin America.
The most vulnerable devices are equipped with the Android operating system, according to a report from the Kaspersky Security Network, the new-threat detection service under Kaspersky Lab, a security technology consulting firm.
From January to June, Kaspersky specialists detected about 47,000 malicious programs (malware) – software used by hackers to disrupt computer operation, obtain information and access private computer systems – with 99% of them targeting the Android operating system.
During the same period last year, Kaspersky registered about 35,000 malware.
“Among the factors that explain why Android is an attractive target for criminals is the growing number of users using devices with this operating system,” said Roberto Martínez, a Kaspersky Lab security analyst. “Other factors are related to its being an open platform and app control isn’t strict.”
Whenever there is an open platform, manufacturers and operators can make modifications to the operating system. Developers can upload their apps to the Android online store without going through any filter, increasing the risk of uploading malware.
Fraudulent apps
In general, the greatest threats are fake apps that take control of the device or steal the owner’s data, according to Alfonso Kejaya, a mobile malware researcher at McAfee Labs Chile, a security solutions company.
For example, a malware can make a smartphone send SMS messages to numbers that charge extra fees per message, thus taking money from a user’s account.
It also can convert the phone into a spy device, providing information about the user, including passwords to bank accounts and social networks.
Another way that malware enters devices is through Wi-Fi wireless networks in airports or public spaces, or through fake chargers in shopping centers that damage cell phones when connected, according to Kaspersky.
The magnet of Latin America
Though malware is a global threat, Latin America is one of the most affected areas, according to Martínez.
“Certainly, the region has become an attractive and growing market because more and more users are using smartphones or tablets because of their low cost,” he said.
Smartphone sales in Latin America in the first quarter of 2013 reached 16.6 million units, a 53% increase compared to the same period in 2012, according to the consulting firm International Data Corporation (IDC).
Android continues to be the best-selling operating system in the world, with a 79.3% share of the smartphone market, according to IDC.
“This has made Latin American markets attractive for cyber-crime as electronic transactions have increased for banking and shopping, using smartphones to make electronic payments,” Kejaya said.
About 31% of smartphone users use mobile e-commerce in Chile – the same figure in Mexico –followed by Brazil (30%), Colombia (28%) and Argentina (21%1), according to a survey on mobile e-commerce in Latin America conducted by Ericsson, a mobile phone company, released in June.
For its part, the Latin American Federation of Banks projects the number of Latin Americans who access their banks via mobile service will increase by 65% each year, reaching 140 million users by 2015.
Greater awareness
Miguel Ángel Varas, the head of Technical Resources at the Infrastructure and Technology Unit of the Department of Information Technology at Chile’s Federico Santa María Technical University, said users must safeguard their devices from malware.
More than 50% of smartphones and tablet owners who use Android don’t protect their devices, according to a survey that included 8,605 respondents from 19 countries in Europe, the Americas, Middle East and the Asia-Pacific region in August 2013 by B2B International and Kaspersky.
Only 40% of smartphone owners and 42% of tablet owners who participated in the survey said they have security software installed on their devices, such as an anti-virus program especially designed for mobile products.
Varas advised users to install apps only from official stores: Play Store for Android, App Store for Apple users and Marketplace for Microsoft users.
“Don’t install unofficial apps under any circumstances,” he warned. “If the permissions requested are suspicious, it is better to refuse to accept them.”
The permissions granted should correspond to the functions performed. For instance, if WhatsApp, an instant messaging app, requests permission to “read our contact data,” it makes sense because it is required to find other users to chat, Varas added.
However, if a game requests the same permission, that’s suspicious, as the malware may be trying to access the list of contacts to send advertising messages, among other possibilities, to all of them.