Home / malwarePDF  

Trojan:Android/DroidKungFu.C


First posted on 23 August 2011.
Source: SecurityHome

Aliases :

There are no other names known for Trojan:Android/DroidKungFu.C.

Explanation :

Trojan:Android/DroidKungFu.C forwards confidential details to a remote server.

Additional Details

Trojan:Android/DroidKungFu.C are distributed on unauthorized Android app sites as trojanized versions of legitimate applications.

Installation

Prior to installation, this new variant of the DroidKungFu family requests the following permissions:



Activity

Once installed, DroidKungFu.C attempts to root the phone (gain control of the system) by using exploits, including RageAgainstTheCage. These exploits are stored in the malware package and encrypted with a key.

The trojan also attempts to collect the following information from the compromised device:

  • International Mobile Equipment Identity (IMEI)
  • Mobile device model
  • Network operator
  • Network type
  • Operating system (OS) APIs
  • OS type
  • Information stored in the Phone memory
  • Information stored in the SD card memory


The collected information is reported to remote command and control (C&C) servers at multiple locations.

More

This trojan was discovered by researchers at the North Carolina State University. For additional information, see:

  • Security Alert: New DroidKungFu Variant -- AGAIN! -- Found in Alternative Android Markets.

Last update 23 August 2011

 

TOP