According to security researchers at Kaspersky, the first Tor-based Trojan for Android has been discovered. The malware, also known as “Backdoor.AndroidOS.Torec.a,” uses the Tor network to communicate with its C&C Server and conceal its illegal activities.
Experts found that Torec.a's operation is based on Orbot, an open source Tor client for Android devices.
Orbot is used to communicate between the C&C server and the Trojan, as well as to send commands to it. Commands include: blocking or intercepting incoming SMS, retrieving information about the phone and installed applications, sending SMS messages to specific phone numbers.
On the one hand, using the Tor network has several advantages, most notably that communication with the C&C server is difficult to disrupt. On the other hand, experts point out that malware developers have used much more code to implement the use of Tor than they have used for the Trojan's functionality.
Additional details about Backdoor.AndroidOS.Torec.a are available on the Kaspersky blog.

