New Android.Wukong steals users' money
Real-time threat news
June 17, 2011
The new versions of the Trojan horse Android.Wukong were built into the software distributed from several sites in China. In particular, it was discovered in one of the largest collections of software at www.nduoa.com, containing more than 11,000 applications.
The malware gets onto a mobile device, when a user downloads an infected application, and runs as a background process of the operating system. Then the Trojan horse receives a paid service number from a remote server and starts sending short messages starting with the string "YZHC" at this number at 50 minute intervals. Besides, the malicious program attempts to hide traces of its activity and removes messages it has sent as well as received payment confirmations from the device's memory.
To date, Doctor Web virus analysts know about seven versions of the malicious software, the corresponding entries have been included into the Dr.Web virus databases. We recommend all users of devices running Android to scan your device with Dr.Web for Android Anti-virus + Anti-spam or Dr.Web for Android Light.

