Android package file
The Trojan may arrive as a package with the following name:
Once installed, the application may display an icon depicting the Android robot with Japanese text.
When the Trojan is being installed, it requests permissions to perform the following actions:
- Access information about networks.
- Open network connections.
- Read contact data.
- Make the phone vibrate.
- Write to external storage devices.
The Trojan gathers the user's contact names and email addresses and stores them in the following location:
The threat then attempts to post the stolen information to the following site:
When the Trojan is executed, it displays an image of a naked cartoon character.
Symantec Security Response encourages all users and administrators to adhere to the following basic security "best practices":