Skip to main content

Trojan:Android/Crusewind

Classification

Category:

Malware

Platform:

Android

Type:

Trojan

Aliases:

  • Trojan:Android/Crusewind.A
  • Crusewind
  • Crusewind.A

Summary

Trojan:Android/Crusewind.A intercepts incoming SMS messages and forwards them to a remote server.

Removal

Technical Details

Installation

Prior to installation, the program detected as Trojan:Android/Crusewind.A will request the following permissions:

Once installed, this trojan displays an application icon in the Applications menu. In the samples we analyzed, the application name used are either 'Flashp' or 'MMS', with differing icons.

Example of Trojan:Android/Crusewind.A using the application name 'MMS'.

Activity

When the user clicks on the application icon, the program appears to simply exit without launching. In the background however, the trojan creates a new service named 'com.flashp.Flashservice':

Service created by Trojan:Android.Crusewind.A

Once the service is active, the trojan will attempt to download an XML configuration file from the following location

  • h t t p://crusewind.net/[...]/test.xml

The downloaded file contains a list of URLs the trojan will attempt to contact to send and receive data. Further details in the XML file are used by the trojan to determine the remote location where an incoming SMS message will be forwarded.

Crusewind.A also uses JSON to serialise and post a list of applications installed on the affected device to a remote server listed in the XML file.

At the time of writing, all URLs listed in the XML file are blocked by F-Secure's Browsing Protection.

Additional

In addition to forwarding SMS messages, the trojan also has the capability to delete them.

Crusewind is also able to check its current version and update itself, or if necessary delete itself.

Protect your devices from malware with F‑Secure Total

Protecting your devices from malicious software is essential for maintaining online security. F‑Secure Total makes this easy, helping you to secure your devices in a brilliantly simple way.

  • Award‑winning antivirus and malware protection

  • Online browsing, banking, and shopping protection

  • 24/7 online identity and data breach monitoring

  • Unlimited VPN service to safe­guard your privacy

  • Password manager with private data protection

Choose how many devices you want to protect to get started.

  • Free customer support

  • Cancel anytime

  • The trial does not obligate you to buy the product

After 30 days your subscription will renew automatically for one year at €69.99.

More Support

Community

Ask questions in our Community.

User guides

Check the user guide for instructions.

Contact Support

Chat with with or call an agent.

Submit a Sample

Submit a file or URL for analysis.