
SonicWALL UTM Research team received reports of a new sophisticated Trojan targeting the android platform. This Trojan called Stiniter/TGLoader is a modified version of an Android game with an additional malicious service. During our analysis we found that the Trojan was installing multiple modules (ELF and APK), contacting a remote command and control server and sending messages to a premium rate number.
When the rogue application is run, it in turn installs 4 ELF executable modules and 3 android applications. The sequence of events on execution is shown below:
The installed android applications use misleading names and were found to be using the following permissions:
It performs the following activities:
SonicWALL Gateway AntiVirus provides protection against this threat with the following signature:
Share This Article

An Article By
An Article By
Security News
Security News