Kaspersky security researchers have identified a new, interesting threat designed exclusively for Android. “SMS.AndroidOS.FakeInst.ef” is an SMS Trojan that targets users in 66 countries.
The threat was first detected in February 2013 and several variants have been released since then.
The first versions of the malware were designed to send text messages to premium-rate numbers in Russia. However, cybercriminals have gradually upgraded the Trojan, adding more and more target countries to the list – which now stands at 66.
While most attacks have been observed in Russia and Canada, countries such as Germany, Lithuania, the United States, France, Finland, Norway, Ukraine, the United Kingdom, Malaysia, Hungary, Switzerland, Indonesia, Spain, Israel, Portugal, Ireland, China, the Czech Republic, the Netherlands, New Zealand, and Brazil are also affected.
The trojan is distributed as an application that supposedly allows users to access adult videos.
Based on the victims' location, the malware is used to send messages from the infected devices to specific premium-rate numbers. For each message, victims are charged approximately $2 (€1.5).
In addition to sending SMS, the trojan can also monitor incoming messages. Experts believe that the threat has been developed by Russian-speaking cybercriminals.

