Analysis by: Echo Duan

 THREAT SUBTYPE:

Information Stealer

 PLATFORM:

Android

 OVERALL RISK RATING:
 DAMAGE POTENTIAL:
 DISTRIBUTION POTENTIAL:
 REPORTED INFECTION:
 INFORMATION EXPOSURE:

  • Threat Type: Trojan

  • Destructiveness: No

  • Encrypted:

  • In the wild: Yes

  OVERVIEW

This malicious app usually poses as a porn video player or system update to entice users to download and install on mobile devices.

Once installed, it requests device admin privileges to prevent uninstall. It shows a fake update message followed by a ransom note.

  TECHNICAL DETAILS

File Size: 43,088 bytes
File Type: APK
Memory Resident: Yes
Initial Samples Received Date: 17 Aug 2016
Payload: Displays graphics/image

NOTES:

This malicious app usually poses as a porn video player or system update to entice users to download and install on mobile devices.

Once installed, it requests device admin privileges to prevent uninstall. After 30 minutes, it shows the following:

While the background service runs, it uploads user personal information including Contacts, GPS data, country data. It also communicates with its C&C server and displays the following ransom note:

The server then sends a series of commands to lock the user screen and to download and install other malware on the device.

  SOLUTION

Minimum Scan Engine: 9.800

Trend Micro Mobile Security Solution

Trend Micro Mobile Security Personal Edition protects Android and iOS smartphones and tablets from malicious and Trojanized applications. It blocks access to malicious websites, increase device performance, and protects your mobile data. You may download the Trend Micro Mobile Security apps from the following sites:


Did this description help? Tell us how we did.