Researchers from Dr. Web finds a new version of the Trojan downloader

Security researchers from the Russian company Doctor Web discovered an interesting para of Trojan downloader. The threat, named Android.MulDrop.18.origin, is designed to download into a infected.

trojan

According to experts, when MulDrop is run on a device it uses a special library to decrypt its components, which include two files. The files are detected as .DownLoader.57.origin and Android.DownLoader.60.origin.

Once enabled, these files start communicating with remote servers from which they receive the list of applications they need to install. The administration and control server can be configured to deliver files at certain intervals.

Among malicious files downloaded from malicious software, researchers identified SMS Trojans as well as spyware such as Android.SmsSend and Android.Backdoor.

Doctor Web researchers have reported that Trojan downloaded applications do not automatically install. Users must confirm the installation. However, experts underline the fact that most users do not give too much attention to what the application installers write.

A second variant of Android.MulDrop.18.origin examined by Doctor Web contained Trojan downloaders in unencrypted form. This is similar to the previous one, but uses different mechanisms to communicate with the command and control server.

iGuRu.gr The Best Technology Site in Greecefgns

every publication, directly to your inbox

Join the 2.087 registrants.

Written by Dimitris

Dimitris hates on Mondays .....

Leave a reply

Your email address is not published. Required fields are mentioned with *

Your message will not be published if:
1. Contains insulting, defamatory, racist, offensive or inappropriate comments.
2. Causes harm to minors.
3. It interferes with the privacy and individual and social rights of other users.
4. Advertises products or services or websites.
5. Contains personal information (address, phone, etc.).