Threat Description

Trojan:​Android/Torsm.A

Details

Aliases:Trojan:​Android/Torsm, Android.Torec.A, Android/Torec.A, Torec, Andr/SMSTor-A, Backdoor.AndroidOS.Torec.a
Category:Malware
Type:Trojan
Platform:Android

Summary



Trojan:Android/Torsm.A is reportedly the first trojan to use the open-source, anonymizing Tor network to hide its communications with its Command & Control (C&C) structure. When active, the trojan monitors and intercepts incoming SMS messages, as well as sends SMSes to a specified number.



Removal



F-Secure's Mobile Security product automatically blocks installation of this program.



Technical Details



When installed, Trojan:Android/Torsm.A will monitor and intercept incoming SMS messages and forward them to a number that can be specified in instructions sent via the C&C server. It can also harvest information from the device, including the phone number, device model and a list of installed apps.

Torsm.A is notable for the way it communicates with the attacker(s) controlling its operations, as the C&C server used by the operators is within the anonymizing Tor network. This makes it extremely difficult for security researchers and law enforcement authorities to takedown the server. Though this technique has been previously used with PC-based malware, this is the first known instance of an Android malware using the same technique to hide its communications.

The code for the Torsm trojan was reportedly based on the available, open-source Orbot Tor client, with additional code to enable the trojan's malicious functions. For more information, see:






SUBMIT A SAMPLE

Suspect a file or URL was wrongly detected? Submit a sample to our Labs for analysis

Submit Now

Scan & clean your PC

F-Secure Online Scanner will scan and clean your PC in just a few minutes for free

Learn More