A Trojan that steals contact details from Android-running devices was spotted with a bogus battery optimization app.
Luring users with the promise of increased battery performance upon installation, the Trojan covertly scans address books and broadcasts phone numbers and email addresses to an attacker-controlled domain.
After sending all contact details, it displays an image with a GONE visibility state, followed by a message saying: “申ã—訳ã”ã–ã„ã¾ã›ゔ。ãŠ使ã„㮠端末ã¯未対応㮠ãŸã‚Âã”利用ã„ãÂًʋӋ¾ã›ゔ“.
Translated from Japanese, it means “I am sorry. Your terminal is not available or unsupported“.
Users then believe the app really isn`t compatible with their handset and usually uninstall it, believing nothing happened.
Although the message is in Japanese, the Trojan is perfectly capable of infecting any Android-running device and scan address books regardless of region or carrier. Why attackers need the phone numbers and email addresses on your device is unknown, but we can speculate that it has something to do with spam campaigns.
The application does nothing to improve battery performance and users are left believing their device was simply incompatible with the app. Even the app`s icon is pretty convincing, displaying a green battery logo.
What`s striking is the simple nature of the Trojan and the high impact it can have. Besides a carefully chosen name that addresses smartphone users plagued by low battery performance, the app`s purpose is straightforward upon closer examination.
All product and company names mentioned herein are for identification purposes only and are the property of, and may be trademarks of, their respective owners.
tags
Liviu Arsene is the proud owner of the secret to the fountain of never-ending energy. That's what's been helping him work his everything off as a passionate tech news editor for the past few years.
View all postsNovember 14, 2024
September 06, 2024