Threat Description

Trojan: Android/BeanBot.A

Details

Category: Malware
Type: Trojan
Platform: Android
Aliases: Trojan:Android/BeanBot.A

Summary


BeanBot.A forwards device's data to a remote server and sends out premium-rate SMS messages from the infected device.



Removal


Automatic action

F-Secure's Mobile Security product blocks installation of this program with default settings.

More scanning & removal options

More information on scanning or removal options are available in the documentation for your F-Secure Mobile Security product on the Downloads section of our Home - Global site.

You may also refer to the Knowledge Base on the F-Secure Community site for more information.

Contact Support

For further assistance, F-Secure customers can request support online via the Request support or the Chat forms on our Home - Global site.



Technical Details


Upon launching, BeanBot.A prompts an 'update' option that would connect to a command and control (C&C) server when clicked on. It then forwards the following information to the server:

  • International Mobile Equipment Identity (IMEI) number
  • International Mobile Subscriber Identity (IMSI) number
  • Phone number

Additionally, BeanBot.A also sends out premium-rate SMS messages from the infected device, leaving the user with a hefty bill charged to his or her account.

BeanBot.A listed as 'BlowUp,' and the permissions it requested upon installation




SUBMIT A SAMPLE

Suspect a file or URL was wrongly detected? Submit a sample to our Labs for analysis

Submit Now

Give And Get Advice

Give advice. Get advice. Share the knowledge on our free discussion forum.

Learn More