New Trojan malware disguises itself as an Android game app

A new Trojan masquerading as a game app is targeting phones running Google's Android OS, subscribing to premium SMS services and sending information about the phone to its controller.

Computer security firm Sophos said the Trojan tags along in a legitimate Chinese game, "The Roar of the Pharaoh," which is not distributed on Google Play (formerly the Android Marketplace).

"Once installed the malicious application gathers sensitive information (IMEI, IMSI, phone model, screen size, platform, phone number, and OS version) and sends it off to the malware's authors. Like many other mobile Trojans, this one sends SMS messages to premium rate SMS numbers and is capable of reading your SMSs as well," Sophos said in a blog post.

Sophos said it detects the malware, which is attached to the game app distributed on unofficial download sites, as Andr/Stiniter-A.

But it also noted the new Trojan is unusual as it does not ask for any specific permissions during installation, which is often an indicator an application is up to no good.

It added the malware masquerades as a service called "GameUpdateService" - a very plausible name for a legitimate app if one were to check the processes running on his or her device.

Also, Sophos said the malware also attempts to communicate with four .com domains with a path of "tgloader-android," leading some to refer to this Trojan as TGLoader.

"Criminals love the free money laundering service provided by mobile phone providers. They can set up premium rate SMS numbers in Europe and Asia with little difficulty," Sophos noted.

It said the mobile phone companies provide the payment processing and the bad guys have their money and are long gone before the victim ever receives the phone bill with the fraudulent charges.

"As always, be sure to only install applications from official sources for the safest smartphone experience. While the sophistication of today's mobile malware is quite low, this won't remain true if there is a buck to be made," Sophos advised. — TJD, GMA News

Loading...

Editor’s note:Yahoo Philippines encourages responsible comments that add dimension to the discussion. No bashing or hate speech, please. You can express your opinion without slamming others or making derogatory remarks.

  • Phl aviation has met int’l safety standards – CAAP
    Phl aviation has met int’l safety standards – CAAP

    The Civil Aviation Authority of the Philippines (CAAP) said that the country’s aviation has met international safety standards and is currently being reviewed by the European Union. Members of the EU delegation recently made a courtesy call on CAAP Director General William Hotchkiss III. Beda Badiola, CAAP’s Flight Standards and Inspectorate Service chief, said all air carriers in the country have followed regulations that the agency was able to oversee properly according to standards. “They …

  • Absence of full-time PNP chief affecting police services
    Absence of full-time PNP chief affecting police services

    Despite the pronouncement of the leadership of the Philippine National Police that it’s business as usual, some basic services are undeniably affected by the absence of a full-time PNP chief, particularly the issuance of gun permits. The PNP had deferred the issuance of permits to carry firearms outside residence (PTCFOR) since Dec. 3, a day before the Office of the Ombudsman slapped a six-month suspension on former PNP chief Director General Alan Purisima, who is facing plunder charges. …

  • Expanded Phl-US war games start today
    Expanded Phl-US war games start today

    The Philippines and the United States will kick off today this year’s Balikatan military exercises amid concerns over China’s reclamation activities in disputed areas in the West Philippine Sea. More than 11,000 Filipino and American troops will join the drills to be held simultaneously in different locations until April 30. …

  • Budol-budol, dugo-dugo scams now online
    Budol-budol, dugo-dugo scams now online

    Authorities warned the public yesterday to be more careful in dealing with people they meet online as the “budol-budol” and “dugo-dugo” gangs have expanded their deceptive operations on social media. Senior Inspector Robert Reyes, assistant chief of the Philippine National Police’s Anti-Cybercrime Group (ACG) investigation section, said online financial fraud is one of the emerging forms of scams in the country. Reyes said scam operators are looking for prospective victims online through …

  • Noy wants next PNP chief to serve beyond his term
    Noy wants next PNP chief to serve beyond his term

    President Aquino is inclined to name a new Philippine National Police (PNP) chief who can serve beyond the 2016 elections. Speaking to reporters at the Tarlac National High School before the weekend, Aquino said he was bewildered by the amended PNP Act that requires all deputies of the PNP chief to serve or stay at least one year in his post. Among the contenders for PNP chief are Deputy Director General Marcelo Garbo Jr., suspended Chief Superintendent Raul Petrasanta and Director Juanito …

  • ‘Stronger global action sought on China moves’
    ‘Stronger global action sought on China moves’

    Stronger international action is needed to counter China’s rapid reclamation activities in the West Philippine Sea, Speaker Feliciano Belmonte Jr. said yesterday. Belmonte noted that statements of condemnation from global powers on the continued encroachment of China in the disputed waters have been ineffectual. He added that China’s blatant expansion activities are making the problem not just a regional security problem, but a global one. “China is obviously violating our territory in front …

  • MILF refusal to surrender fighters jeopardizing talks
    MILF refusal to surrender fighters jeopardizing talks

    Leaders of the House of Representatives renewed their call yesterday to the Moro Islamic Liberation Front (MILF) to surrender its fighters allegedly involved in the killing of 44 police commandos in Mamasapano, Maguindanao last Jan. 25. Leyte Rep. Ferdinand Martin Romualdez, leader of the House independent bloc, said the continued refusal of MILF leaders to turn over their men is causing the further erosion of support for the proposed Bangsamoro Basic Law (BBL) in Congress. “I hope the MILF …

  • China ignores global outcry vs reclamation
    China ignores global outcry vs reclamation

    On Wednesday, G-7 foreign ministers issued a Declaration on Maritime Security expressing alarm over “unilateral actions, such as large scale land reclamation, which change the status quo and increase tensions” in the region. In their communiqué, which did not specifically mention China, the ministers expressed belief that reclamation activities were meant to “change the status quo” in the West Philippine Sea and South China Sea, through which 40 percent of global trade passes. …

POLL

Should Aquino be held accountable over the Mamasapano operations?

Loading...
Poll Choice Options