500,000 Android Devices Infected in Six Hours by SMS Worm in China

Status
Not open for further replies.

Petrovic

Level 64
Thread author
Verified
Honorary Member
Top Poster
Well-known
Apr 25, 2013
5,355
The Chinese Valentine’s Day was on August 2 this year and it was the perfect opportunity for cybercriminals to conduct nefarious activities, as they delivered an SMS worm for Android that spread faster than love, affecting a total of 500,000 devices in about six hours.

Security researchers analyzing a sample observed that the malware contained two modules, one for distributing the threat (XXshenqi.apk) and another for performing the malicious activity (Trogoogle.apk).

Propagation is carried out through short text messages, which carry a link to the malicious download, to the entire lists of contacts, Vigi Zhang from Kaspersky says.

Once landed on the device, the malware, detected as Trojan.AndroidOS.Xshqi.a by Kaspersky products, it drops a backdoor that collects user's personal ID and name, sending them to a command and control server.

The backdoor is identified as Backdoor.AndroidOS.Trogle.a by the products of the security company and it has been crafted to work stealthily on the mobile device by hiding its icon after installation; as such, many users may not be aware of its presence.

Among the commands it can execute if so instructed by the command and control server, are reading and sending messages. Zhang notes the malware can also send the text to its owner either by email or by using the short message service.

The attack seems to have been premeditated by the threat actors, in order to make the most of the campaign, since users are likely to be less vigilant on special occasions. Also contributing to the success of the campaign is the fact that the malware download is received from a known contact.
 
Status
Not open for further replies.

About us

  • MalwareTips is a community-driven platform providing the latest information and resources on malware and cyber threats. Our team of experienced professionals and passionate volunteers work to keep the internet safe and secure. We provide accurate, up-to-date information and strive to build a strong and supportive community dedicated to cybersecurity.

User Menu

Follow us

Follow us on Facebook or Twitter to know first about the latest cybersecurity incidents and malware threats.

Top