Security researchers from Kaspersky have discovered the first Tor-based Android Trojan. The Trojan, dubbed Backdoor.AndroidOS.Torec.a, uses the anonymous Tor network to hide its communications.
According to experts, Torec.a is based on Orbot, an open source Tor client for Android mobile devices.
Orbot's functionality is used to send commands from the Trojan's command and control (C&C) server. The list of commands the malware receives includes blocking incoming SMS, intercepting incoming SMS, retrieving information about the phone and installed applications, and sending SMS messages to a specific number.
Using Tor to communicate with the C&C has several advantages, such as the fact that the communications infrastructure is more difficult to disrupt and detect. On the other hand, experts emphasize that malware developers have developed more code to implement the use of Tor than for the functionality of the Trojan itself.
Additional details about Backdoor.AndroidOS.Torec.a are available on the Kaspersky blog.
