Trojan-Spy:SymbOS/Flexispy.A is a spyphone application that allows a user to monitor calls and messages on a targeted phone. The application must be manually installed on the phone in order for the program to operate.
Note: there are newer versions of FlexiSPY than the variant described here. Later versions exhibit different behavior and are not classified as malware.
Flexispy.A is installed in a standard SIS package and when installed the application uses the name "phones". It does not give any indication as to what is being installed.
After installation the application will immediately go into hiding and locks its files so that the application uninstaller cannot remove it.
The user interface of Flexispy.A is only accessible by entering a special code in the phone number field.
In the user interface, the attacker can control when the spying application reports and what information is recorded.
Flexispy.A records both voice call and SMS information and sends the details to the FlexiSpy server. From there the information can be accessed through a web browser.
Flexispy.A records the following details from the victim's voice calls:
Flexispy.A records the following details from the victim's SMS message traffic:
F-Secure Anti-Virus detects this malware with the following updates:[FSAV_Database_Version]
F-Secure Mobile Anti-Virus for Symbian detects this malware starting from the update build number 81.
Description Created: 2006-03-29 15:10:58.0
Description Last Modified: 2010-06-10 09:38:08.0