Researchers from security firm Doctor Web have identified an interesting and quite dangerous trojan downloader for Android. The threat, known as Android.MulDrop.18.origin, is designed to download malware to infected devices.
Experts point out that when executed, MulDrop uses a special library to decrypt its contents and two files – which are detected as Android.DownLoader.57.origin and Android.DownLoader.60.origin – are unpacked.
Once activated, these components begin communicating with remote servers, from which they receive the list of applications they need to install.
The command and control server can be configured to push malicious applications in batches, at specific time intervals.
Among the software being downloaded, researchers have identified SMS Trojans and spyware, such as Android.SmsSend and Android.Backdoor.
Dr Web notes that applications pushed by the Trojan are not installed automatically. Users must confirm the installation. However, experts emphasize that many users do not pay close attention to what they install on their smartphones.
Another variant of Android.MulDrop.18.origin has been detected by researchers, which includes the trojan downloader in an unencrypted form. This malware is similar, but uses different mechanisms to communicate with the command and control server.
