Threat Description

Trojan:​Android/Voxv.B

Details

Aliases: Trojan:​Android/Voxv, Andr/Voxv-B, Android.Trojan.Voxv, Trojan.AndroidOS.Voxv
Category: Malware
Type: Trojan
Platform: Android

Summary



Trojan:Android/Voxv.B is a trojanized version of a popular game app that harvests and silently forwards sensitive details from the infected device to remote contacts.



Removal



F-Secure's Mobile Security product blocks installation of this program with default settings.



Technical Details



Trojan:Android/Voxv.B is a trojanized version of the legitimate and popular game app 2048 Puzzle. The trojan uses the same name and look as the original app, but requests more permissions than the legitimate game, including permission for writing, reading and sending SMS messages. Due to the similarity between the legimitate and trojanized apps, users would need to be alert to the additional permissions requested by the trojan to be able to differentiate between them.

Once installed, the trojan collects the following details from the device:

  • International Mobile Subscriber Identity (IMSI) number
  • International Mobile Equipment Identity (IMEI) number
  • Device type, brand, model and release version
  • Device ID, SIM serial number and phone number (line1)
  • API level and display type
  • List of installed apps

These details are silently forwarded to specified remote servers; some of the details are also sent via SMS to a specified phone number.

In additiona to data harvesting, the trojan also checks the device for the presence of a specific app with the package name 'com.lbe.security' (LBE Security Master Application). This appears to be a security utility program intended for Chinese language users.






SUBMIT A SAMPLE

Suspect a file or URL was wrongly detected? Submit a sample to our Labs for analysis

Submit Now

Scan & clean your PC

F-Secure Online Scanner will scan and clean your PC in just a few minutes for free

Learn More