AndroidOS_KeepSpy.NGPCA

 Analysis by: Earl Jewel Valiente

 ALIASES:

Trojan-SMS.AndroidOS.Agent (IKARUS), TrojanSMS.Agent.DQA (NOD32)

 PLATFORM:

Android

 OVERALL RISK RATING:
 DAMAGE POTENTIAL:
 DISTRIBUTION POTENTIAL:
 REPORTED INFECTION:
 INFORMATION EXPOSURE:

  • Threat Type: Trojan Spy

  • Destructiveness: No

  • Encrypted:

  • In the wild: Yes

  TECHNICAL DETAILS

File Size:

2,311,681 bytes

File Type:

APK

Memory Resident:

No

Initial Samples Received Date:

04 Dec 2023

Payload:

Steals information

Other Details

This Trojan Spy does the following:

  • Get and Replace Default SMS Package
  • Send SMS
  • Protect Source Code
  • Obfuscate Package Name
  • Application is also signed by a Debug Certificate

Mobile Malware Routine

This Trojan Spy is a file that collects the following information on an affected mobile device:

  • Device Running Processes
  • Device Running Services
  • Device Installed Applications
  • Device Accounts
  • Device Phone Numbers
  • Device Manufacturer
  • Device Model

  SOLUTION

Minimum Scan Engine:

9.800

Trend Micro Mobile Security Solution

Trend Micro Mobile Security Personal Edition protects Android and iOS smartphones and tablets from malicious and Trojanized applications. It blocks access to malicious websites, increase device performance, and protects your mobile data. You may download the Trend Micro Mobile Security apps from the following sites:


Did this description help? Tell us how we did.