New Android.Wukong steals users' money

Real-time threat news

June 17, 2011

On June 17 2011 Doctor Web—a renown Russian anti-virus vendor— added signatures of four new modifications of Android.Wukong (4-7) into the virus databases. This malicious programs targetting Android OS send paid short messages to steal money from user accounts.

The new versions of the Trojan horse Android.Wukong were built into the software distributed from several sites in China. In particular, it was discovered in one of the largest collections of software at www.nduoa.com, containing more than 11,000 applications.

image

The malware gets onto a mobile device, when a user downloads an infected application, and runs as a background process of the operating system. Then the Trojan horse receives a paid service number from a remote server and starts sending short messages starting with the string "YZHC" at this number at 50 minute intervals. Besides, the malicious program attempts to hide traces of its activity and removes messages it has sent as well as received payment confirmations from the device's memory.

image

To date, Doctor Web virus analysts know about seven versions of the malicious software, the corresponding entries have been included into the Dr.Web virus databases. We recommend all users of devices running Android to scan your device with Dr.Web for Android Anti-virus + Anti-spam or Dr.Web for Android Light.

0
Latest All news