A Trojan for Android mobile devices. It is an SMS Trojan that can send short messages to premium numbers. The malicious program can be distributed in the guise of an installer of some application.
Once it is installed and launched, the malware prompts the user to grant it administrative privileges. Then it hides its shortcut that is located on the home screen.
The malicious program gathers the following device-related information and sends it to the command and control server:
- IMEI
- Balance (acquired using an USSD request)
- Country code
- Phone number
- Operator code
- Device model
- OS version
The malware can execute the following commands:
- Send an SMS containing a specified text to a specified number
- Send out SMS messages to contacts from the phone book
- Load a specified URL in the browser window
- Display a dialogue window with a specially generated title and text