Simple clear advice in plain English

Android hack that disables tablets and phones targets older versions

400 million Ice Cream Sandwich, Honeycomb and Gingerbread users urged to upgrade

SIM card in a HTC Flyer tablet
The attack on Android phones can block SIM cards

Around 400 million people using Android devices are vulnerable to a new attack that wipes all data or disables phones and tablets, security experts have warned.

The very simple attack on a growing number of Android devices uses a flaw in the Unstructured Supplementary Service Data (USSD) code devices, which are used to communicate with the user's service provider's computers for tasks such as call back or balance enquiries.

The attack is launched automatically if someone visits a website on which the malicious code is embedded. It affects version of the Android operating system earliuer than Jelly Bean 4.1.

Read more: Android news | App reviews

The code then tricks the USSD's automatic dialler feature, which makes placing phone calls easier while the user is browsing the web.

The Android device sees this code as a phone number, which then allows the hackers to repeatedly change the PIN code in the SIM or the personal unblocking, key (PUK). The attack also shows the phone's IMEI number.

There appear to be no financial motives behind this attack.

Alexandru Balan of Bitdefender said: "Most malware attacks are motivated by financial gain but not this one. The motive appears to be a prank or making life difficult for someone and it is so easy to carry out that anyone could do this and take revenge on someone."

The user will only realise this after the phone has been switched off and find they are unable to turn it back on as a different PIN has been set. It will also wipe all the data from Samsung devices. To use the device again the user has to get a new SIM from their service provider.

Only devices using Google's latest Android 4.1 Jelly Bean operating system are not vulnerable to this attack. There is also protection for the Samsung Galaxy S III.

However only around two per cent of Android users have Jelly Bean, and older devices will not upgrade to this OS. These people will have to protect themselves in other ways.

Security firms have developed free protection, such as Eset's USSD Control, Bitdefender's Wipe Stopper and G Data's USSD Check, which can be downloaded from Google Play.

There is more about this exploit along with a video at the Dylan Reeve website.

Reader Comments

USSDD THREAT

htc wildfire open to this no upgrade likely ever! sony xperia ray still waiting for upgrade for this one! reluctant to after poor reviews so ive installed patch and bought bitdefender for both phones jusst prooves that nowt is secure shame on htc for abandoning wildfire and shame on sony for their buggy updates

Posted by neil2047, 13 Oct 2012

Updates

I would update to jelly bean on my 1X, still waiting for HTC to release it. I've installed AV and Bitdefender's wipe stopper. Manufacturers should quicker in releasing patches.

Posted by Singh1970, 16 Oct 2012

   

Add your comment

Please keep comments constructive and free from abuse of any kind and swearing. If you wish to link to a product or service online, please do so in such a way that makes it clear that it is not spam. If you are connected to any such product you should make that clear.

We may use your comments in the magazine. We may edit your comments for clarity or to remove unacceptable material. We will attribute your comments but not share your email address.

We request your email address and record your Internet Address (IP address) in order to block spam from our site. We will never share this information without your permission.

All comments are reviewed by the Computeractive Team before being published. Please bear with the slight delay this causes, you don't need to post more than once.

Click here to read our Privacy Policy

Click here to read our site Terms & Conditions

Related articles

mobileapp-androidmalwarecheck

Aggressive adware causes problems for Android tablets and phones

Bitdefender warns ads can drain battery life, push up data usage and change settings without permission

Google Android Malware

Fake Android apps flourish as virus threat to mobile phones grows

London Olympics and the end of Adobe mobile flash player spark summer of fake Android apps

Android settings screen

How can I move and erase the data on my old Android smartphone?

A reader asks how to wipe an Android phone's data so it is inaccessible to anyone else, while keeping apps for a new phone

Content Recommendation

Question & Answer

Q.Why is Windows Backup skipping files?

> Read the answer

Q.Why do my scanned documents display gibberish?

> Read the answer

Q.How can I convert MTS files to edit in Windows Movie...

> Read the answer

Best deals on the web

img

Samsung NP350E7C-A04UK

£349.99- Buy it now

img

Toshiba Satellite C850D-11Q (PSCC2E-00R00JEN)

£279.97- Buy it now

img

ASUS Eee PC X101CH-BLK043S

£239.99- Buy it now

Updating your subscription status Loading

Most popular articles

No matching document

Poll

Do you have Windows 8?

Jargon Buster

Computing terms explained in plain English

CAD

Computer Aided Design. Software used to create 3D models.

Great shopping deals from Computeractive

Information currently unavailable