Analysis by: Peter Yan

 THREAT SUBTYPE:

Premium Service Abuser

 PLATFORM:

Android

 OVERALL RISK RATING:
 DAMAGE POTENTIAL:
 DISTRIBUTION POTENTIAL:
 REPORTED INFECTION:
 INFORMATION EXPOSURE:

  • Threat Type: Trojan

  • Destructiveness: No

  • Encrypted:

  • In the wild: Yes

  TECHNICAL DETAILS

NOTES:

This malware is a legitimate app repackaged with malicious code. The malicious code is disguised to resemble the legitimate SDK named umeng. This is to avoid detection.

It registers its malicious routines as a legitimate activity as well as an SMS receiver.

Once installed, it requests ads from a possibly malicious URL, and send subscription messages to a premium service number via the Java Native Interface (JNI). It also intercepts received messages to conceal the charges incurred from the user.

  SOLUTION

Minimum Scan Engine: 9.700

Remove unwanted apps on your Android mobile device

[ Learn More ]

Did this description help? Tell us how we did.