Android package file
The Trojan may arrive as a package with the following characteristics:
Kakao Talk Security
When the Trojan is being installed, it requests permissions to perform the following actions:
- Monitor, read, create, and send SMS messages
- Read user's contacts data
- Change the phone state, such as powering it on and off
- Write to external storage devices
- Open network connections
Once installed, the application will display an icon of a yellow square with a black speech bubble containing the word "TALK."
When the Trojan is executed, it checks to see if any of the following security products are running on the compromised device:
Next, the Trojan opens a back door on the device and connects to the following command-and-control (C&C) server:
The Trojan then sends SMS messages to all contacts stored on the device.
Symantec Security Response encourages all users and administrators to adhere to the following basic security "best practices":