During the development process, the creator of the Xbot Android malware inserted an offensive string into the code that targets antivirus, possibly because the software was not going through the detection process.
Xbot has been detected in unofficial Android app marketplaces that supposedly provide popular products such as the Opera browser , Minecraft, or even Google Play .
This particular malware is not a standalone application, as the creator simply added malicious code to embed it into legitimate products.
Avast researchers monitored Xbot's activity and observed that over 350 unique files were distributed through third-party marketplaces since early February.
Security company's telemetry data showed that more than 2,570 installations were performed based on unique GUIDs (Globally Unique Identifier).
After infection, the malicious software runs a routine to ensure its persistence on the system and starts its activity after the device reboots. It also requests a large number of dodgy permissions that currently focus on logging, reading, and writing short text messages.
Among the available functions, monitoring of incoming text messages for certain keywords and uploading them to a remote Command & Control (C&C) server is included.
An additional feature involves sending SMS from the infected device to selected numbers. This is used to send texts to premium-rate numbers, as observed by Avast during analysis of various malware.
There is also the capability of retrieving content from a link provided by the C & C server, which can also send commands to monitor the device.
It is not unusual for malware creators to embed text strings that have nothing to do with the threat code. In the case of Shylock, also known as Caphaw, the programmers added small excerpts from Shakespeare’s “The Merchant of Venice”.
However, things are not at all literary in the case of Xbot, as the author included a small comment: //(new StringBuilder (“[expletive]_U_AV” )).append(“1″).toString();”
“Messages like this are nothing new in malware, as security companies like Avast can really cut into the revenue of the bad guys from this type of malware,” Avast’s Jan Sirmer said in a blog post on Tuesday.
The researchers discovered samples of Xbot scattered across Eastern Europe. They report that its creator may be planning to add a new feature designed to log incoming calls. This function exists, but is currently disabled, indicating that the project is still under development.
