Summary
Trojan:Android/DroidKungFu.C forwards confidential details to a remote server.
Disinfection & Removal
Automatic
F-Secure's Mobile Security product blocks installation of this program with default settings.
Manual Removal
Monitoring-Tool:Android/DroidKungFu.C can be uninstalled by following the steps below:
- Go toSettings
- Go toApplications
- Go toManage Applications
- Select the application
- Press "Clear data"
- Press "Uninstall"
- Select "OK" when asked for confirmation and wait
Technical Details
Trojan:Android/DroidKungFu.C are distributed on unauthorized Android app sites as trojanized versions of legitimate applications.
Installation
Prior to installation, this new variant of the DroidKungFu family requests the following permissions:
Activity
Once installed, DroidKungFu.C attempts to root the phone (gain control of the system) by using exploits, including RageAgainstTheCage. These exploits are stored in the malware package and encrypted with a key.
The trojan also attempts to collect the following information from the compromised device:
- International Mobile Equipment Identity (IMEI)
- Mobile device model
- Network operator
- Network type
- Operating system (OS) APIs
- OS type
- Information stored in the Phone memory
- Information stored in the SD card memory
The collected information is reported to remote command and control (C&C) servers at multiple locations:
- http://[...]search.gongfu-android.com:8511/[...]search/
- http://[...]search.zi18.com:8511/[...]search/
- http://[...]search.zs169.com:8511/[...]search/
More
This trojan was discovered by researchers at the North Carolina State University. For additional information, see:
Submit a sample
Wondering if a file or URL is malicious? Submit a sample to our Lab for analysis via the Sample Analysis System (SAS)
Give And Get Advice
Give advice. Get advice. Share the knowledge on our free discussion forum.
Keep your mobile device protected

F-Secure Mobile Security will keep your mobile device protected on the go and enable you to find it in case you lose it