Softpedia
 

NEWS CATEGORIES:



NEWS ARCHIVE >>
SOFTPEDIA REVIEWS >>
MEET THE EDITORS >>
TRENDING TODAY
Home > News > Security

January 14th, 2012, 09:39 GMT · By Eduard Kovacs

Android NFL Game Drops IRC Bot and SMS Trojan

SHARE:

Adjust text size:

Android Trojan creates a Madden NFL 12 menu icon
Enlarge picture
Security researchers are coming across a large number of pieces of malware that target Android devices lately. The latest is a malicious application that displays itself as the Madden NFL 12 game, carrying a set of components that get dropped onto the infected device.

Kaspersky Lab Experts have analyzed the Trojan and even though they couldn’t exactly determine how it spreads, they've managed to find out how it works and the extent of the damage it can cause.

The Trojan, a 5 megabyte file, drops a payload composed of a root exploit, Exploit.Linux.Lotoor.ac, an SMS Trojan, identified as Trojan-SMS.AndroidOS.Foncy.a, and an IRC bot.

So you may wonder how these malicious elements work in harmony.

First of all, a .class file called AndroidBotActivity creates a directory and sets read, write and execute permissions for all the users, after that extracting three .png files, representing the SMS Trojan, the root exploit and the IRC bot.

After the operation is complete, an error message is displayed on the screen, saying that the application is not registered, but in reality, the root exploit is executed. If the device is rooted, the IRC bot is launched, which in turn installs the SMS Trojan.

The IRC bot connects to a server, on a certain channel, with a random nickname and awaits shell commands from the server, executing them on the infected device.

This is not the first time we hear of the Foncy SMS Trojan and it seems that it hasn’t changed much since we've last seen it. Just as before, it tries to send SMSs to premium-rate numbers from countries such as France, Belgium, Germany and Canada, at the same time blocking the messages that come from these numbers.

Unlike the previous variant, where the cybercriminals counted the number of victims by sending the incoming messages to a phone number, in this scenario, the messages that come from the premium-rate numbers were uploaded to a remote server.


2,033 hits
Link to this article · Print article · Send to friend

MUST-READ RELATED ARTICLES:


Carrier IQ Detection Tools Modified to Become SMS Trojans

Scareware Migrates to Android Devices, Beware of Opera Virus Scanner

Angry Birds and Kamikaze Killers, Perfect Recipe for a Scam

60 Infected Online Games Sites Redirect Users to Malicious Domains

Sykipot Trojan Improved to Hijack DoD Smart Cards

READER COMMENTS:



No user comments yet.
Be the first to express your opinion!
Copyright © 2001-2013 Softpedia. Contact/Tip us at

WindowsGamesDriversMacLinuxScriptsMobileHandheldNews

SUBMIT PROGRAM   |   ADVERTISE   |   GET HELP   |   SEND US FEEDBACK   |   RSS FEEDS   |   UPDATE YOUR SOFTWARE   |   ROMANIAN FORUM