Fortinet Blog | News and Threat Research

  • Products
  • Solutions
  • Service & Support
  • Partners
  • Corporate
  • Resources
  • How to Buy

Android malware distributed by malicious SMS in France

by RSS Axelle Apvrille  |  September 21, 2012  |  Category: Security Research

Another Android malware is currently in the wild in France, as we have recently discovered.

This malware poses as a Flash Player installer and steals your incoming SMS messages by forwarding them to a remote server. We have named it Android/Fakelash.A!tr.spy.

Contrary to many Android malware which are downloaded from underground or legitimate marketplaces (see here, here, here, here… ), this one is propagating via a link in a SMS. For example, the victim below complains he received an SMS from 10052 saying “For proper function of your device, please download the new ANDROID Flash update at this link: http://tinyurl.com/xxxxx”.

Victim complaining of infection by Android/Fakelash.A!tr.spy

In this particular case, the victim reports he installed the virus, but later uninstalled it because he felt somewhat uncertain about the fact the package requested many permissions and was downloaded from an unknown server.

Indeed, the malware would contact a remote server for configuration data such as incoming phone numbers to spy. By uploading a fake configuration file to our emulators, we were able to catch the packets the malware would have been sending out - of course, we blocked those outgoing packets.

The malware is forwarding an incoming SMS to a remote server (censored URL). The text of the SMS was “hithere”, and the SMS was sent by phone number “1234

On PCs, posing as Flash Player update or sending spam to get promote the malware is relatively common. On Android, it is not. For instance, malware authors prefer to infect a well-known game and post it on a third-party market place. So, it is an option that Android/Fakelash.A!tr.spy comes from a PC-virus gang who has recently taken interest into Android. If that is the case, it can only be bad news for our mobile devices…

Please be cautious with this sample because, as far as we know, apart from Fortinet, nobody detects it yet.

Detection coverage as of Sept 20, 2012

Finally, I would conclude with a warning to French users. Our country is not immune to mobile malware and you need to be cautious with what you see or install on your phones.

Thanks to Guillaume Lovet for his insights on this post.

– the Crypto Girl

by RSS Axelle Apvrille  |  September 21, 2012  |  Category: Security Research
Tags: android Flash Player france Malware sms trojan spyware
comments powered by Disqus

Category

  • All
  • RSS Subscribe
  • Security Research
  • RSS Subscribe
  • Industry Trends & News
  • RSS Subscribe

FortiGuard Labs on the Web

  • Twitter Twitter
  • Facebook Facebook
  • LinkedIn LinkedIn
  • Youtube Youtube

Monthly Archives

  • May 2013 7
  • April 2013 17
  • March 2013 12
  • February 2013 11
  • January 2013 12
  • December 2012 8
  • November 2012 7
  • October 2012 4
  • September 2012 7
  • August 2012 7
  • July 2012 9
  • June 2012 17
  • May 2012 14
  • April 2012 16
  • March 2012 15
  • February 2012 11
  • January 2012 6
  • December 2011 4
  • November 2011 6
  • October 2011 11
  • September 2011 2
  • August 2011 2
  • July 2011 4
  • June 2011 6
  • May 2011 6
  • April 2011 5
  • March 2011 7
  • February 2011 5
  • January 2011 7
  • December 2010 8
  • November 2010 11
  • October 2010 3
  • September 2010 8
  • August 2010 4
  • July 2010 9
  • June 2010 9
  • May 2010 9
  • April 2010 6
  • March 2010 8
  • February 2010 6
  • January 2010 9
  • December 2009 8
  • November 2009 6
  • October 2009 6
  • September 2009 8
  • August 2009 5
  • July 2009 8
  • June 2009 7
  • May 2009 4
  • April 2009 7
  • March 2009 9
  • February 2009 4
  • January 2009 1
  • Older

Popular topics

adobe mobile malware facebook UTM reversing iphone symbianos android Fortinet derek manky webinar botnet Threat Landscape Anonymous Firewall Zeus exploit challenge virut Windows Security reverse engineering conference zitmo Antivirus symbian Research SpyEye hacking challenge Cryptography stuxnet privacy google hashdays Malware FortiGate mobile phones BYOD symbos/yxes Mobile Security trojan sms Mac OS X mobile microsoft network security mobile phone Anti-Spam bredolab apple