Skip to main content

Brador

Classification

Category:

Malware

Aliases:

  • Brador
  • Backdoor.WinCE.Brador.a

Summary

Brador is the first known backdoor for the Pocket PC hand-held devices.

When run, the backdoor copies itself to startup folder, mails the IP address of the PDA to the backdoor author and starts listening commands on a TCP port. The hacker can then connect back to the PDA via TCP port and control the PDA through the backdoor.

NOT FOUND

Brador has not been seen in the wild. It only runs on ARM-based Pocket PC devices that have Windows Mobile 2003 (Windows CE 4.2) or later.

Brador is a backdoor, not a virus. It will not spread on it's own.

Removal

Technical Details

Installation to system

When run the Brador will copy itself to Windows\StartUp directory as svchost.exe on the Pocket PC device, so that it will automatically start at each time when device boots.

The installation routine makes slight modifications to the file copied to Windows\StartUp directory. So the file will be a bit different at each boot, although this will not affect the operation of the backdoor. It is still unclear whether this is intentional or side effect of the installation routine.

Payload

When the Brador has installed itself into the system it will read the local host IP address and email that to the author.

After emailing it's IP address the backdoor opens a TCP port and start listening commands from it.

The backdoor is capable of uploading and downloading files from PDA, executing arbitrary commands and displaying messages to the PDA user.

Protect your devices from malware with F‑Secure Total

Protecting your devices from malicious software is essential for maintaining online security. F‑Secure Total makes this easy, helping you to secure your devices in a brilliantly simple way.

  • Award‑winning antivirus and malware protection

  • Online browsing, banking, and shopping protection

  • 24/7 online identity and data breach monitoring

  • Unlimited VPN service to safe­guard your privacy

  • Password manager with private data protection

Choose how many devices you want to protect to get started.

  • Free customer support

  • Cancel anytime

  • The trial does not obligate you to buy the product

After 30 days your subscription will renew automatically for one year at €69.99.

More Support

Community

Ask questions in our Community.

User guides

Check the user guide for instructions.

Contact Support

Chat with with or call an agent.

Submit a Sample

Submit a file or URL for analysis.