Trojan-Spy:Android/Smforw

Threat description

Details

Category: Malware
Type: Trojan
Platform: Android
Aliases: Trojan-Spy:Android/Smforw, android.SMForw, AndroidOS.SmForw, Andr/KSmsSpy-A, Android.Fakeguard

Summary


Trojan-Spy:Android/Smforw variants silently forward incoming SMS messages on an infected device to a remote server.



Removal


Automatic action

F-Secure SAFE automatically blocks installation of this program.



Technical Details


Trojan-Spy:Android/Smforw variants may be installed on a mobile device as part of the payload of a PC-based trojan, Droidpak. When this trojan infects a Windows system, it downloads a mobile app onto the machine and then attempts to install it onto any Android devices connected to the system by a USB cable. For installation to be successful, the device must have the setting 'Enable USB debugging' enabled.

When installed, SMforw variants will monitor and intercept incoming SMS messages and forward them to a remote server.






SUBMIT A SAMPLE

Suspect a file or URL was wrongly detected? Submit a sample to our Labs for analysis

Submit Now

Give And Get Advice

Give advice. Get advice. Share the knowledge on our free discussion forum.

Learn More