The threat is advertised as an application for a Chinese gaming community and may arrive as an application package with the following name:
When executed, the Trojan attempts to send premium-rate SMS messages to one or more of the following numbers:
It then attempts to remove the SMS messages it sends from the device.
The Trojan sends device information, such as IMEI and IMSI numbers, to the following URLs:
The Trojan may also download and install updates.
Symantec Security Response encourages all users and administrators to adhere to the following basic security "best practices":