A new Android Trojan could steal your data through mobile messaging apps like Facebook Messenger, Twitter, and Skype.
This malware was discovered by security researchers at Trustlook, an online security firm. A report published on Monday describes the new Trojan as simple and with few features.
After infecting the application, the Trojan attempts to modify the “/system/etc/install-recovery.sh” file to trigger its execution every time the application is opened.
It appears that the primary purpose of this malware is to steal data from messaging applications, which is later uploaded to a remote server. The Trojan retrieves the IP address of this server from a local configuration file.
Here is the list of applications that may be affected by this malware:
- Facebook Messenger
- Skype
- Telegram Messenger
- Tencent WeChat
- Viber
- Voxer Walkie Talkie Messenger
- Gruveo Magic Call
- Line
- Coco
- BeeTalk
- TalkBox Voice Messenger
- Momo
Although it has a simple design and focuses solely on extracting messaging app, this malware uses some advanced techniques to make it undetectable.
According to Trustlook Labs, the Trojan disguises its configuration file and part of its malicious code to avoid detection, making it difficult for antivirus software to detect.
Since this particular Android Trojan has a single goal (to steal data), it is very likely that its creators are trying to collect sensitive information and data through private conversations, images, and videos that they could later use to blackmail their victims.
Although it is unclear where this malware originated, Trustlab researchers traced it to a Chinese app called Cloud Module, appearing as com.android.boxa.
Considering that the malware has a Chinese name, and given the unavailability of the Play Store in China, its creators are very likely spreading it through links on Android app forums or through unofficial app stores and third-party websites.
