Android package files
The Trojan is available for download in the Android Market as an application package from the following publishers:
- iApps7 Inc.
- Ogre Games
- redmicapps
Applications from these publishers include but are not limited to the following:
- com.iapps.hitterrorist
- com.iapps.hitterroristpro
- com.christmasgame.balloon
- com.christmasgame.deal
- com.redmicapps.puzzles.ladies3
Permissions
When the Trojan is being installed, it may request permissions to perform the following actions:
- Access information about networks
- Access information about the WiFi state
- Access location information, such as Cell-ID, GPS, or WiFi
- Allows access to install and uninstall shortcuts
- Allows access to read settings on the device
- Allows access to the list of accounts in the Accounts Service
- Check the phone's current state
- Make the phone vibrate
- Open network connections
- Prevent processor from sleeping or screen from dimming
- Read and write access of the user's browsing history and bookmarks
- Start once the device has finished booting
Functionality
The listed apps all contain a similar package called com.apperhand which has functionality similar to com.plankton found in
Android.Tonclank and may perform the following actions on the compromised device:
- Copy bookmarks on the device
- Copy opt out details
- Copy push notifications
- Copy shortcuts
- Identify the last executed command
- Modify the browser's home page
- Steal build information (for example: brand, device, manufacturer, model, OS, etc.)
The Trojan may attempt to connect to the following remote locations:
- [http://]www.apperhand.com/ProtocolGW/prot[REMOVED]
- [http://]www.searchmobileonline.com/[CATE[REMOVED]
Applications from Ogre Games have the additional functionality to retrieve the following information from the device:
- Android ID
- IMEI
- IMSI
- MAC address
- SIM serial number
Symantec Security Response encourages all users and administrators to adhere to the following basic security "best practices":