Home > Threat descriptions >



Category:  Riskware

Type:  Riskware

Platform:  Android

Aliases:  Riskware:Android/Smssend.variant!Online, Android.Riskware.SMSSend, SMSSend.[variant]


This detection from the F-Secure Security Cloud identifies Android apps that contain an additional module for sending SMS messages to premium-rate numbers (see Trojan:Android/SmsSend). This behavior can lead to unexpectedly high telephony or data charges, if the user is unaware of the app's capabilities.


Automatic action

Once the scan is complete, the F-Secure security product will prompt you to assess the file and choose to Uninstall, Quarantine or keep it installed on your device.

Knowledge Base

Find the latest advice in our Community Knowledge Base.

About the product

See the manual for your F-Secure product on the Help Center.

Contact Support

Chat with or call an expert for help.

Submit a sample

Submit a file or URL for further analysis.

Technical Details

F-Secure Security Cloud is an online reputation service that provides the latest analysis and reputation rating for programs, files and websites. If a questionable program or file is found during a scan, a query is sent to the Security Cloud to get the most recent reputation rating for it.

Based on the settings of your F-Secure security product, it will then use the information from Security Cloud (and if needed, further analysis) to determine whether to delete, quarantine or block the program or file.

The Security Cloud rating for the identified app indicates that it contains an additional module for sending SMS messages to premium-rate numbers. Such apps are grouped in the family, Trojan:Android/SmsSend.

SmsSend variants send SMS messages to premium-rate numbers. The app's SMS-sending behavior may result in unexpectedly high phone charges if the user is unaware of the app's capabilities. This behavior may also be legally questionable, depending on the jurisdiction and if it is done without the user's knowledge or consent.

A specific SmsSend variant may be detected as either riskware or a trojan, depending whether the program performs other malicious actions.