The Delf-HA Trojan contacts a Web site for details on which spam campaign to run and then randomly generates a series of Russian mobile numbers beginning with the prefix +7921 or +7911. It logs into the SMS sites of the Russian mobile phone companies to distribute the campaign.
It is all automatic so much of the virus's time is wasted sending spam to unallocated numbers. Most of the spam is for Russian music sites.
So far the Delf-HA targets only Russian mobile networks, but Sophos thinks that it is only a matter of time before the trick is seen in other countries.
A spokesSophos said that SMS spam is rare, but if the spammers work out a way of automating it, such as they have in Delf-HA, it could be a lot more common. ยต