Five minutes turns into 10, then into 20, and suddenly you realize you're
very late for your call home. You approach your pocket and pull out your
Bluetooth-enabled smart phone, but you are unable to dial out.
A message across the display says that someone from a Panasonic phone wants
to send you a message-yes or no? You look around and quickly realize that you
probably don't know anyone at the sports bar, so you thumb 'no'.
But the message again returns. And this keeps on repeating. Do you know what
to do next? Do you even suspect or realize that your mobile device is about to
be infected with one of about 150 known mobile-device viruses?
It's not too surprising then that Nokia's S60 third-edition phones-Nokia N71,
Nokia E60, Nokia E61 and Nokia E70-come preinstalled with F-Secure Mobile
Anti-virus.
![]() |
| By: Mikko Hypponen |
Safe platforms
Essentially, for mobile viruses to exist, there must be a dominant operating
system. After years of proprietary, and therefore diverse operating systems,
smart phone manuÂfacturers have begun adopting Symbian 8 as their platform of
choice.
Currently, Symbian occupies about 70 percent of the world market for all
phones, and Microsoft Windows Mobile about 10 percent, while the rest is a
combination of lesser-used platforms (such as Palm OS). In the US, Symbian is
only about 10 percent of the market. Thus, they have not seen or been affected
by mobile device viruses, as Europe and southeast Asia have.
Smart phones will soon replace our laptop or desktop PCs, if not our credit
cards and personal key rings. With this in mind, the idea that a virus could
cripple your smart phone starts to take on much more meaning than just not being
able to make a personal phone call; a mobile device
virus could one day steal your identity or lock you out of your house.
Mobile devices can get infected in four known ways, with Bluetooth being the
most harmful. You'd think that after years of e-mail-based computer viruses,
people would know how not to infect themselves with a virus.
For example, they shouldn't open an attachment sent by a stranger. But in
this scenario, the new message prompt keeps coming and you absolutely,
positively have to make that phone call home now. So, out of frustration, you
submit and thumb 'yes'. The messages stop coming, and you make your phone call,
but your smart phone has been infected, and it's broadcasting out to whatever
Bluetooth-enabled devices are in your immediate vicinity.
Knowing what to do
Bluetooth has a limited range. Once you leave that range, you stop getting
the new message prompt, and you'll be free to make your call.
Most people don't realize this. The most common response when we ask, “How
did your cell phone get infected?” is that victims answered 'yes' so they could
make a call. And like a human virus, once someone's mobile device is infected,
it's likely to pass that infection to other, then another.
F-Secure had documented a Finnish businessman who returned from a business
trip to India and proceeded to walk around his town with the
Cabir virus broadcasting itself to whatever Bluetooth-enabled devices it could
find.
Soon, Cabir began to show up in other European countries. Europe and
southeast Asia still have the largest concentration of Cabir infections in the
world.
![]() |
| If a mobile device is infected, it's likely to pass that infection to other phones, then another |
Memory cards
The second way a mobile device can become infected is through memory cards
pre-infected with the Skulls Trojan, another mobile-device virus. Since the
Trojan doesn't propagate via conventional means (Bluetooth or e-mail), there is
no danger to other mobile devices in the immediate vicinity-so long as you
didn't give any of them your infected memory card.
But within 10 seconds of inserting the infected memory card, even a mobile
smart phone can get infected. The memory card circumvents the built-in security.
If people start sharing memory cards to swap photos and music on their phones,
we could start seeing viruses spreading much faster in the mobile universe. This
method might also install a Bluetooth virus.
MMS and downloads
A third way for a mobile device to get infected is via multimedia message
service (MMS) viruses such as Commwarrior. With MMS, you don't have to be in the
vicinity of another mobile device; an infected mobile device can send an MMS
message to anyone in the world.
So, using the phone books of infected mobile devices, Commwarrior has
traveled the world-again, using smart phones based on the Symbian OS. But here,
the phone service provider can filter out infected MMS messages, and many have
done so. Thus, Commwarrior hasn't proven to be a major threat to mobile devices.
Finally, the fourth method of mobile device virus propagation is to embed the
infection within a download-a common practice with PC-based viruses and spyware.
Here, you can imagine people downloading a custom ring tone or a new mobile
device game only to find their smart phone disabled.
Protection is coming
Like F-Secure, McAfee and Symantec also have mobile anti-virus apps in the
market. All three ant-virus vendors have partnered with smart phone
manufacturers around the world to provide preinstalled protection.
In the very near future, I expect that all mobile devices will have some form
of anti-virus protection. But whether they will take the form of anti-virus and
OS partnership, anti-virus and manufacturer partnership, or end-user choice of
anti-virus application, is unclear.
Mobile device viruses are not currently linked with organized crime because
there's no financial incentive. Yet, once people start online banking using
their mobile devices or using mobile devices as debit cards or the
authentication method of choice, you can expect that to change.
(The author is Director of Antivirus Research at F-Secure)
/dqc/media/agency_attachments/2026/08/21/2026-08-21t061716244z-dq-channels-logojpg-2026-08-21-11-47-17.jpeg)
/dqc/media/media_files/2026/09/10/dq-channels-whatsapp-2026-09-10-17-07-48.png)
Follow Us/dqc/media/post_attachments/704a93467597609b901f5b82501e5c72554cb7b5697bd37013183bde0e48d807.jpg)
/dqc/media/post_attachments/1c591eff163b2ba3bf6475272a249e9b44261ca783360b4c5397975213fda4da.jpg)