Home / malwarePDF  

Trojan:Android/AVPass.C


First posted on 10 April 2014.
Source: F-Secure

Aliases :

There are no other names known for Trojan:Android/AVPass.C.

Explanation :

Trojan:Android/AVPass.C is distributed in the guise of a Clock app; while active however, it steals information from the device and attempts to uninstall or bypass security-related apps installed on the device.

Technical Details
Trojan:Android/AVPass.C is distributed in an app named 'Clock'. On installation, it creates several app icons in the device's App menu panel. The icons are named "system update", "360Antivirus" and "QQ"; the last two names refer to popular apps, but none of the icons actually lead to a program.

Clicking any of the icons silently starts the trojan in the background, while the newly created app icons are deleted. Meanwhile, the trojan harvests the following details from the device:

SMS message and calls log GPS location data Contacts data Stored photos Phone's recording data

In addition, the trojan checks to see if any security/antivirus apps on an internal list are installed on the device. If found, the trojan requests for user root privileges in order to uninstall the security/antivirus app, or bypass it by modifying its database to prevent detection of the app.

Last update 10 April 2014

 

TOP