Android package file
The Trojan may arrive as a package with the following characteristics:
When the Trojan is being installed, it requests permissions to perform the following actions:
- Access information about and change the WiFi state
- Create, read, and send SMS messages
- Monitor incoming SMS messages
- Mount and unmount file systems for removable storage
- Open network connections
- Start once the device has finished booting
- Write to external storage devices
Once installed, the application will display an icon of a green robot with a white cube on its chest.
When the Trojan is executed, it will send an SMS message to the following number:
The Trojan will then remove its icon from the apps list.
Next, the Trojan will record and send SMS messages on the compromised device to the following location:
The Trojan may also block SMS messages from being viewed by the user.
Symantec Security Response encourages all users and administrators to adhere to the following basic security "best practices":