Security researchers have discovered a malicious Android Trojan codenamed Android/Trojan.Pawost that is embedded within a stopwatch app, but uses Google Talk to initiate phone calls to unregistered numbers.
Pawost begins its malicious behavior as soon as users install it. Once this happens, the app displays a Google Talk icon in the smartphone. There is no text on this icon and the updates are a dead giveaway that something is wrong and you should uninstall the app as soon as possible.
A few minutes later, the app will start making calls to various unknown numbers, using the Google Talk.
While Pawost is making these calls, the phone's screen is off, but the CPU is active and working.
The mystery surrounding these phone calls is that they are not made to a valid number. They all start with the same sequence: 1-259.
Adding the US international prefix +1 at the beginning does not connect to any valid number. The area code 259 is not assigned to the US, so the campaign is definitely not targeting US users.
Since Pawost was bundled with an Android app with a Chinese interface, Malwarebytes tried to add China's international prefix +86.
Their test calls connected to valid numbers, but everything seemed to indicate they were talking. At this point, it was clear that the app was targeting Chinese users.
Security researchers took a closer look at the Pawost malware and said that in addition to making these illegal calls, the app also has spyware capabilities.
The malware can collect data such as IMSI codes, IMEI numbers, CCID identifiers, phone numbers, phone version details, as well as a list of applications installed on the device.
Pawost takes this data, encrypts it, and sends it to a remote server. In addition, the trojan can send SMS messages and block incoming SMS messages. Malwarebytes said it found this latter functionality in Pawost's decompiled source code, but it was never observed in its tests.
Whatever it is, it's certainly in its early stages of development. Apparently, Pawost is set to become an Android trojan that infects Chinese users and then makes calls or sends SMS messages to premium phone numbers, helping the scammers behind this malware make money through affiliate programs.


