SMS is used widely
Mobile text SMS (Short Message Service) is a regular convenience for billions of mobile users worldwide. The technology, which has remained unchanged since the 1990s, is a part of our mobile banking, email account 2FA, personal and business communication, and other regular messages and updates like those from grocery and food delivery services, scheduling a reminder to our clients and business partners or employees, and updates from government agencies.
SMS is highly unsecure
But do you know that SMS is a highly unsecure form of communication, based on legacy technologies from when cybersecurity threats and concerns were not as prevalent or fully understood? SMS lacks end-to-end encryption, which makes it highly vulnerable to interception via man-in-the-middle attacks, and it also exposes all communication details to the telecom provider and the government, including the contents of the SMS in plain text. This makes it a highly unsecure form of two-factor authentication compared with more secure options, like app-based 2FA, 2FA via secure USB keys, and one-time backed-up passwords saved securely in an encrypted vault.
Various threats when using SMS
a) Malware: Notable dangers of using SMS come from the client side, present on the end user device. Android malware like Gorilla and Qwizzserial are specifically designed to intercept SMS to steal banking and other one-time passwords, which is a breach of a critical layer of security used by banks to verify financial transactions, and thus violates the financial integrity of users.
b) Vulnerabilities in Devices: Another danger to SMS users comes from vulnerabilities in the digital, social, financial and business ecosystems of which most people are a part. For example, infected 4G/5G routers have been found to secretly send SMS messages to drain users' bank accounts. A phishing-as-a-service (PhaaS) platform named ‘Lucid’ was in the news, targeting 169 entities in 88 countries using well-crafted messages sent over iMessage (iOS) and Android. Scammers and phishers are known to leverage RCS technology to send messages in bulk, as sending traditional SMS in bulk can incur significant costs. Recently, a Voice Over Wi-Fi vulnerability let attackers eavesdrop on calls and SMS.
c) Vulnerabilities in Telecom Infrastructure: The dangers to the digital security of SMS users also come from many other points of compromise. For example, as has been seen in the recent compromises of telecom infrastructure in the US and Turkey by Chinese threat actors like Salt Typhoon, likely sponsored by the Chinese government, the security of unencrypted forms of mobile communication, including SMS, is at risk — so much so that the US has dropped the idea of invading consumer encryption technologies used for secure communication, and is encouraging the use of encrypted communication for both official purposes and by citizens, to keep information of vital national importance from falling into the hands of adversaries.
d) Dangers from State Level Threats: Dangers to SMS users also come from targeted state-level attacks, even by their own governments. Malicious SMS can be used to infect targets in zero-click or single-click attacks with mercenary spyware like Pegasus, Graphite, Hermit and others, to spy on users, including their SMS texts and other personal information, by secretly gaining complete control of the user device.
e) SIM Swapping Attacks: Another grave danger to SMS users comes from SIM swapping attacks, where a threat actor is able to get a copy of the user's SIM via fraudulent documents and personal details, and thus is able to intercept the user's SMSs, including banking OTPs, and can drain users' bank accounts.
f) Phishing and Social Engineering Attacks: But perhaps the biggest and most common threat to mobile users worldwide, all of whom rely on SMS in one way or another, comes from fraudulent and phishing SMS, made more effective by the use of social engineering tactics based on user information derived from social media handles and posts. These target users' vulnerabilities and entice them into a fraudulent scheme, or into clicking a malicious link, to harm the user in significant ways and to produce substantial gains for the attacker. This can include investment and pig-butchering frauds, fraudulent crypto investment schemes, links to fake shopping sites intended to steal credit card details, and links to malicious APK files that entice users to install the file and give it all the permissions, making it possible for the attacker to operate the device remotely using command and control servers and carry out fraudulent transactions.
Sending fraudulent SMS to mobile users takes place not just at a limited individual scale, but also at a mass scale, using SMS blasters, such as the one Thai police recently neutralised, which sent 100,000 SMS per hour and was used to target Bangkok residents. Fake mobile stations can also be set up to send and intercept text messages.
g) SMS users are affected by Spam: Last but not least, SMS, considering how little control users have over the entire experience, combined with the above threats, is a constant source of recurring spam messages, drawing user attention and disturbing them, which indirectly causes users to be harmed by malicious SMS received in the future, by making it impossible for the user to be careful and critical of each and every message due to their high volume and disturbing or irrelevant content.
How to Safeguard Yourself
a) Using Encrypted Chat Apps over SMS: To safeguard themselves, users should try switching to the newer standard RCS (Rich Communication Services), which brings significant advancements over SMS, albeit with its own set of challenges. Users can download and use the Google Messages app, which brings the advantage of verified senders, spam filtering and E2EE. E2EE in RCS is present on the same Android platform between Android devices using the Google Messages app, and does not have cross-platform compatibility, making RCS message communication between an Android and an iOS device unsecure, although efforts are being made by Apple and Google to address this issue. Also, RCS implementations by carriers like AT&T and Verizon might lack E2EE, with messages resorting to text SMS. These inconsistencies and deficiencies in RCS are the reason why users should be careful, and prefer encrypted chat apps like Signal over text messages.
b) By Being Vigilant: Further, users should certainly be vigilant when clicking on links, and should be aware of and look for signs of device compromise (SDC) to help prevent getting infected by malware, safeguard themselves from phishing, and take appropriate action in case of a malware infection on their devices to prevent threats to mobile banking and their finances.
c) Using Malloc for enhanced Security and Privacy: Users will benefit from also installing a good security and privacy app, like Malloc, available for Android and iOS, which comes with a range of security and privacy features to help protect against mobile threats, including SMS-based phishing, spyware, malware, adware, scareware, and other rogue apps. This is risk reduction rather than a guarantee: no consumer app can cover every mobile threat. Further, Malloc is constantly being updated with new features, and will be adding a dedicated SMS-based on-device security scan, which will alert users to SMS-based threats while also preserving user privacy and security. Detection runs on the device, and the wider mobile security picture is covered here.
Until next time, stay secure and protect your privacy with Malloc!
References:
- cyberinsider.com — Thai police neutralise SMS blaster
- securityonline.info — Qwizzserial SMS stealer
- techradar.com — Google moves Gmail authentication off SMS
- helpnetsecurity.com — SMS stealer threat
- gbhackers.com — Voice over Wi-Fi eavesdropping risk
- forbes.com — New Android password stealer via SMS
- forbes.com — Why you should stop sending texts on your iPhone
- forbes.com — FBI warning on text messages
- forbes.com — Why you should stop texting
- wired.com — On-device AI scam texts
- krebsonsecurity.com — SMS phishing triad pivots to banks
- infosecurity-magazine.com — SMS stealer targets 600 brands
- infosecurity-magazine.com — US officials impersonated via SMS
- forbes.com — Android warning as SMS attacks surge
- cybersecuritynews.com — Qwizzserial as legitimate apps
- cybersecuritynews.com — Chinese mobile forensic tooling
- techcrunch.com — New SMS scam operation emerges
- forbes.com — SMS attacks without your phone number
- bleepingcomputer.com — Phishing platform Lucid
- cybernews.com — Mobile router sends SMS to drain accounts
- bleepingcomputer.com — SMS stealer campaign in 113 countries
- gbhackers.com — Gorilla Android malware
- wired.com — Salt Typhoon telecoms
- techradar.com — Salt Typhoon technique
- techradar.com — Canadian telecom firms
- cyberinsider.com — Turkey dismantles spy network
Relevant tags:
Published on Medium