Home > Threat descriptions >

Trojan-Spy:Android/Smforw

Classification

Category: Malware

Type: Trojan-Spy

Platform: Android

Aliases: Trojan-Spy:Android/Smforw, android.SMForw, AndroidOS.SmForw, Andr/KSmsSpy-A, Android.Fakeguard

Summary


Trojan-Spy:Android/Smforw variants silently forward incoming SMS messages on an infected device to a remote server.

Removal


Automatic action

F-Secure SAFE automatically blocks installation of this program.

Knowledge Base

Find the latest advice in our Community Knowledge Base.

About the product

See the manual for your F-Secure product on the Help Center.

Contact Support

Chat with or call an expert for help.

Submit a sample

Submit a file or URL for further analysis.

Technical Details


Trojan-Spy:Android/Smforw variants may be installed on a mobile device as part of the payload of a PC-based trojan, Droidpak. When this trojan infects a Windows system, it downloads a mobile app onto the machine and then attempts to install it onto any Android devices connected to the system by a USB cable. For installation to be successful, the device must have the setting 'Enable USB debugging' enabled.

When installed, SMforw variants will monitor and intercept incoming SMS messages and forward them to a remote server.