Researchers at Symantec Corp. have discovered a new worm that attempts to attack smartphones running Windows CE platform on ARM processors.
Symantec said the worm is polymorphic, meaning it mutates based on the type of traffic it encounters to evade intrusion defense systems. Once the worm compromises a smartphone it spreads by making copies of itself and begins reaping havoc, including making unwanted phone calls to premium phone numbers, said Symantec software engineer Andrea Lelli.
"It spreads by generating new polymorphic copies of itself each time, and can cause a severe nuisance on a compromised phone," Lelli said in the Symantec Security Response blog.
The new worm is smarter than previous smartphone worms discovered in the wild. It spreads via storage cards rather than via Bluetooth, which quickly drains batteries.
Called WinCE.Pmcryptic.A, the new worm bricks the cell phone by cycling through different screen colors until the screen turns black, Lelli said. The worm also eventually overloads the smartphone capacity.
So far the threat of being infected is low. Victims can eventually delete all the worm executables, but file system menu folders and system colors need to be reset to their default values. Lelli warned Windows CE users to pay attention to the storage cards they plug into the smartphone.
"Unfortunately, WinCE does not provide, by default, tools for doing this, so it is likely that an infected user will need to download and run third-party tools in order to bring order back to the compromised device," Lelli said.