Riskware:Android/SmsPay.variant!Online

Threat description

Details

CATEGORYRiskware
TYPERiskware
PLATFORMAndroid

Summary

This detection from the F-Secure Security Cloud indicates the presence of characteristics or behavior that matches a known Riskware program - Riskware:Android/SmsPay.

Riskware:Android/SmsPay is an Android app that has been repackaged to contain an additional SMS-sending module that can lead to unexpectedly high telephony or data charges, if the user is unaware of the behavior.

Removal

Automatic action

The F-Secure security product will automatically prompt you for a desired action. You may choose to Uninstall, Quarantine or keep the file.

More scanning & removal options

More information on the scanning and removal options available in your F-Secure product can be found in the Help Center.

You may also refer to the Knowledge Base on the F-Secure Community site for more assistance.

Technical Details

SmsPay variants are typically repackaged apps, which are legitimate programs that have been recompiled with additional components and then redistributed.

SmsPay apps contain an additional module to send and receive SMS messages. While not malicious in itself, such functionality is also commonly misused by Android malware to silently send premium-rate or spam SMS messages.

The app's SMS-sending behavior may result in unexpectedly high phone charges if the user is unaware of the app's capabilities. This behavior may also be legally questionable, depending on the jurisdiction and whether it is done without the knowledge or authorization of the user.

About the Security Cloud

F-Secure Security Cloud is a cloud-based threat analysis system that maintains a security rating for common programs, files and websites.

When an F-Secure security product encounters a suspect program or file, it sends a query over the Internet to the Security Cloud and checks for the latest rating available for the program (that is, whether it has already been rated as 'safe' or 'harmful'). Based on the rating, the security product may then either quarantine the suspect file, block it or allow it to proceed.

For more information about the Security Cloud, see:

Submit a Sample

Suspect a file or URL was wrongly detected?
Send it to our Labs for further analysis

Submit a Sample

Protect your life on every device

F-Secure SAFE looks out for you and the people close to you, on every device, all the time.

More Info