A Brazilian virus writer has unleashed a new mobile phone virus, called Lasco.A, that is capable of spreading both through the short-range wireless Bluetooth technology and by attaching itself to files, according to the Finnish anti-virus company F-Secure.
"This is the first time we have come across a mobile phone virus that has two spreading mechanisms," said Mikko Hypp"nen, director of anti-virus research at F-Secure.
The virus affects mobile phones running the Symbian operating system with Nokia's Series 60 interface.
The Lasco.A virus will copy itself inside all SIS (Symbian Installation System) files, which are used to install applications, such as games, according to Hypp"nen. The virus is activated when users click on the SIS file and install it on their phones.
Users can catch the virus unknowingly by swapping files, such as games, among themselves, according to Hypp"nen. "They can swap files by beaming data to each other's handsets with Bluetooth and infrared or by using memory cards and even cables," he said.
The malware also acts like a worm by scanning Bluetooth-enabled phones in the vicinity and attempting to pass on the corrupt file to others, according to Hypp"nen. In this case, however, handset owners must often accept the file from unknown users.
Unlike the Skulls Trojan horse, which displays skulls on displays of infected phones, Lasco.A gives few signs that phones are infected. "Short battery life is probably the most evident indicator," Hypp"nen said. "The infected SIS files are larger but most users won't spot this. Prompting during installation is also different but, again, most users will think this is part of normal installation."
So far, Lasco.A is proof-of-concept virus only, according to Hypp"nen. "We have received no reports," he said. "However, we think this virus will end up in the wild because someone, eventually, will download it, and this virus has the potential to spread very quickly."
To protect their handsets, users should set them to hidden Bluetooth mode, and not discoverable mode, said F-Secure.