{"id":1613,"date":"2025-02-23T15:21:35","date_gmt":"2025-02-23T15:21:35","guid":{"rendered":"https:\/\/threats.amnpardaz.com\/en\/?p=1613"},"modified":"2025-05-07T07:42:18","modified_gmt":"2025-05-07T07:42:18","slug":"trojan-android-smsspy-det","status":"publish","type":"post","link":"https:\/\/threats.amnpardaz.com\/en\/2025\/02\/23\/trojan-android-smsspy-det\/","title":{"rendered":"Trojan.Android.SmsSpy.DET"},"content":{"rendered":"<h2>Overview<\/h2>\n<p>Type: Trojan<\/p>\n<p>Destruction Degree: Medium<\/p>\n<p>Prevalence: Medium<\/p>\n<p>&nbsp;<\/p>\n<h3>Malware Names<\/h3>\n<p><em>(Padvish) Trojan.Android.SmsSpy.DET<\/em><br \/>\n<em>(Kaspersky) HEUR:Trojan.AndroidOS.Hiddapp.ay<\/em><br \/>\n<em>(BitDefenderFalx) Android.Trojan.SpyAgent.OK<\/em><br \/>\n<em>(ESET) A Variant Of Android\/Spy.Agent.DET<\/em><\/p>\n<p>&nbsp;<\/p>\n<h3>What is a Trojan?<\/h3>\n<p>A Trojan is a type of malware that masquerades as legitimate software, presenting itself as functional and benign. However, once executed, it performs malicious actions that can cause significant damage to the system. Trojans infiltrate systems through various methods, including:<br \/>\n\u2022 Downloading software from untrusted sources,<br \/>\n\u2022 Embedded malicious code in HTML files,<br \/>\n\u2022 Malicious email attachments, and more.<\/p>\n<p>&nbsp;<\/p>\n<h3><strong>What is the SmsSpy Malware Family?<\/strong><\/h3>\n<p>The SmsSpy malware family consists of a set of malicious applications designed to steal sensitive user information, specifically targeting bank account details. These apps are often distributed through reputable Android markets such as Cafe Bazaar and Myket, as well as through less trustworthy platforms like unofficial websites, Telegram channels, and SMS messages containing malicious links. While these applications may appear legitimate and useful at first glance, they are designed to deceive users and steal personal data through phishing techniques.<\/p>\n<p>The malware&#8217;s operation typically begins with deceptive promises of offering additional services (such as access to Legal Notice, subsidies, or Justice Shares). If the user is tricked into paying a small fee, they are redirected to a fake bank page. When users enter their login credentials, the malware captures their banking information. Given the malware\u2019s access to SMS messages, it can also retrieve the user\u2019s second-factor authentication code, providing complete access to the compromised account.<\/p>\n<p>&nbsp;<\/p>\n<h2><strong>Technical Description<\/strong><\/h2>\n<h3><strong>Indicators of Compromise<\/strong> (IoCs)<\/h3>\n<ul>\n<li>Requests for dangerous permissions, including access to SMS messages, contacts, installed applications lists, etc.<\/li>\n<li>Unusual spikes in battery consumption and system resource usage (CPU, RAM).<\/li>\n<li>Fake notifications.<\/li>\n<\/ul>\n<h3><strong>Technical Overview<\/strong><\/h3>\n<p>Once the malware \u201cEdalat Hamrah\u201d receives the necessary permissions (including access to SMS messages, contacts, notifications, and call data), it launches a web view that directs users to a phishing page designed to extract payment information. This is how the malware steals bank card details by exploiting the permissions it has been granted. Additionally, the malware is capable of listing installed applications, executing hidden USSD codes, and taking screenshots of the compromised device.<\/p>\n<p>&nbsp;<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter wp-image-4372\" src=\"http:\/\/threats.amnpardaz.com\/wp-content\/uploads\/sites\/2\/2025\/02\/\u0628\u062f\u0627\u0641\u0632\u0627\u0631-\u0639\u062f\u0627\u0644\u062a-\u0647\u0645\u0631\u0627\u0647.png\" alt=\"\u0628\u062f\u0627\u0641\u0632\u0627\u0631 \u0639\u062f\u0627\u0644\u062a \u0647\u0645\u0631\u0627\u0647\" width=\"1664\" height=\"555\" \/><\/p>\n<figure class=\"gallery-item\">\n<div class=\"gallery-icon portrait\"><\/div>\n<\/figure>\n<figure class=\"gallery-item\">\n<div class=\"gallery-icon portrait\"><\/div>\n<\/figure>\n<figure class=\"gallery-item\">\n<div class=\"gallery-icon portrait\"><\/div>\n<\/figure>\n<p>A notable feature of this malware ,shown in the above images, is the static captcha code displayed during phishing attempts, which does not change between page reloads. The dates shown on the page are outdated, indicating that previous versions of this malware family are still being utilized. The malware periodically evolves, with slight changes to its code structure. After a period of dormancy, it resurfaces through social networks and unreliable sources, continuing the cycle of phishing attacks.<\/p>\n<p>&nbsp;<\/p>\n<h4>\u25fd <span style=\"color: #0000ff\"><strong>Main Activity: com.x.team.main<\/strong><\/span><\/h4>\n<p><strong><span style=\"color: #0000ff\">\u25ab\ufe0f <\/span><em><span style=\"color: #3366ff\">ResumableSub_Activity_Create Class<\/span><br \/>\n<\/em><\/strong><\/p>\n<p>This class is integral to the malware\u2019s execution process and runs asynchronously. During the initial phase, the malware checks for necessary permissions, verifies internet and Google services connectivity, and loads the phishing web page step by step within this class. This class can pause execution and resume from the point it left off after receiving results from other methods (such as permission requests or server data retrieval).<\/p>\n<p>The malware uses a state management system in the resume() method, utilizing switch-case and variable state to determine the stage of execution. It terminates its execution in two cases:<\/p>\n<ul>\n<li>In emulators running on Intel processors.<\/li>\n<li>If the SIM card\u2019s country code (retrieved via the getSimCountryIso method) is not \u201cIR\u201d (Iran), the malware displays an error message and terminates its execution.<\/li>\n<\/ul>\n<p>&nbsp;<\/p>\n<p><strong>\u25ab\ufe0f <span style=\"color: #3366ff\"><em>ResumableSub_GetConfigs Class<\/em><\/span><\/strong><\/p>\n<p>This class is responsible for sending a request to the C2 (Command and Control) server to retrieve the malware\u2019s configurations. These configurations may include control commands, new server addresses, communication ports, and other sensitive data required for performing malicious activities. The server address to which the malware sends the initial request is obtained from the method vvvvvvvvvvvv7_. The initial request is sent to obtain the original address to load it into the malware\u2019s WebView.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter wp-image-4366\" src=\"http:\/\/threats.amnpardaz.com\/wp-content\/uploads\/sites\/2\/2025\/02\/\u06a9\u0644\u0627\u0633-ResumableSub_GetConfigs.png\" alt=\"\u06a9\u0644\u0627\u0633 ResumableSub_GetConfigs\" width=\"435\" height=\"162\" \/><\/p>\n<p>The method tries to read the server address from the Domain.txt file. If the file does not exist, it retrieves the value from the vvvvvvvvvvvv0_ method. The server address is then stored in the v5_ server variable and saved to the Domain.txt file. This method utilizes the code to encrypt and decrypt C2 server\u2019s main addresses that is written in Domain.txt file.<\/p>\n<p>After decryption, the -v5 value consists of a list of \u00a0the following C2 server addresses which is also written in the Domain.txt file:<\/p>\n<p><span style=\"color: #0000ff\"><em>https[:]\/\/api0.x-pdomain-zrc9w6pj3a.store\/X.php A-K-U-M-A<\/em><\/span><br \/>\n<span style=\"color: #0000ff\"><em>https[:]\/\/api1.x-pdomain-zrc9w6pj3a.store\/X.php A-K-U-M-A<\/em><\/span><br \/>\n<span style=\"color: #0000ff\"><em>https[:]\/\/api2.x-pdomain-zrc9w6pj3a.store\/X.php A-K-U-M-A<\/em><\/span><br \/>\n<span style=\"color: #0000ff\"><em>https[:]\/\/api3.x-pdomain-zrc9w6pj3a.store\/X.php A-K-U-M-A<\/em><\/span><br \/>\n<span style=\"color: #0000ff\"><em>https[:]\/\/api4.x-pdomain-zrc9w6pj3a.store\/X.php<\/em><\/span><\/p>\n<p>Once the initial connection is made to the server, the malware retrieves additional configuration data, which is stored as a JSON file in the data\/data\/com.x.team\/files directory, named config.json. This file contains critical operational data, including commands, permissions, and security settings that are usually created after reading the Domain.txt file and tell the malware how to behave. These include:<\/p>\n<ul>\n<li>The malware\u2019s phishing page URL (<span style=\"color: #0000ff\">https:\/\/ikdplc.org\/c\/app.php<\/span>).<\/li>\n<li>Requested permissions.<\/li>\n<li>Admin panel requests.<\/li>\n<li>Initial malicious actions, such as the collection of banking and contact information.<\/li>\n<li>Offline communication settings.<\/li>\n<\/ul>\n<p>&nbsp;<\/p>\n<p><span style=\"color: #3366ff\"><strong>\u25ab\ufe0f <em>ResumableSub_ScreenShot Class<\/em><\/strong><\/span><\/p>\n<p>The primary function of this class is to capture screenshots of the victim\u2019s device and send them to the C2 server. The malware captures the current activity screen of the device and saves it (Bitmap) in the file AkumaScreenShot.jpg. This file is subsequently uploaded to the server using the send_screen_ method. Along with the screenshot, the following information is sent:<\/p>\n<ul>\n<li>Operation type (here, &#8220;screenshot&#8221;).<\/li>\n<li>Device model.<\/li>\n<li>Android version.<\/li>\n<li>Port used by the malware.<\/li>\n<li>Screen status (whether the screen is on or off).<\/li>\n<\/ul>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter wp-image-4367\" src=\"http:\/\/threats.amnpardaz.com\/wp-content\/uploads\/sites\/2\/2025\/02\/2-\u06a9\u0644\u0627\u0633-ResumableSub_ScreenShot.png\" alt=\"\u06a9\u0644\u0627\u0633 ResumableSub_ScreenShot\" width=\"506\" height=\"360\" \/><\/p>\n<h4><span style=\"color: #800080\"><strong>? <em>com.x.team.r4 Service<\/em><\/strong><\/span><\/h4>\n<p>The r4 service functions as a foreground service with several malicious capabilities. Using the vvvvvvvvvvvvvvvvvvvvvvv0_ method, it generates a fake notification titled &#8220;Settings&#8221; with the message &#8220;Receiving data&#8221; to disguise its activity. This helps prevent the malware from being easily terminated. The malware also changes its application icon to appear as a &#8220;settings&#8221; icon using the changeicon_ method, further concealing its malicious intent. The original malware icon is hidden via the hideicon_ method to make it harder for the user to remove. Additionally, the r4 service sets up a receiver that checks for the malware every 3 seconds, restarting it if necessary to maintain persistence.<\/p>\n<h4><span style=\"color: #800080\"><strong>? <em>com.x.team.r6 Service<\/em><\/strong><\/span><\/h4>\n<p>The r6 service runs an automated process called AutoTar, which operates in the foreground via a hidden notification. If the system attempts to terminate the service, it is automatically restarted. This service sends device information to the C2 server. The vvvvvvvvvvvvvvvvvvvvvvvvvvv3_ method is used by the service to creates a fake notification that appears as a system update process. \u00a0Then, the malware uses the runautotar_ method to execute an automated process that is responsible for sending device information to the malware server and then propagating malicious SMS messages to the victim\u2019s contacts. The input parameter str in the method contains the text of the SMS message that is to be sent to the user&#8217;s contacts, then the send_autotarstart_ method sends the victim&#8217;s device information, including Android ID, phone model, communication port, request time, and message ID, to the malware server. After a 30-second delay, the vvvvvvvv5_ method is triggered, sending the malicious SMS to the victim&#8217;s contact list. After sending the malicious SMS messages, the service temporarily halts to avoid detection.<\/p>\n<h4><strong><span style=\"color: #800080\">? <\/span><em><span style=\"color: #800080\">com.x.team.firebasemessaging Receiver<\/span><br \/>\n<\/em><\/strong><\/h4>\n<p>The <strong>firebasemessaging<\/strong> receiver, receives incoming messages from the C2 server via Firebase Cloud Messaging FCM). This receiver acts as a communication channel, executing commands received from the server to perform malicious actions on the victim&#8217;s device. These commands include sending SMS messages, stealing bank and credit card information, extracting contacts, retrieving SMS messages, and executing USSD codes to steal account balances. This receiver processes and executes the attacker&#8217;s desired commands received from the Firebase server through the resume method (in the ResumableSub_ProcessFCMMessage class).<\/p>\n<p>Malicious Commands and Their Functions:<\/p>\n<ul>\n<li><span style=\"color: #993300\">oneping<\/span>: Sends basic information about the victim\u2019s phone, such as the model, Android ID, installed apps list, received bank messages, contacts, etc.<\/li>\n<li><span style=\"color: #993300\">allping<\/span>: Collects comprehensive data about the device\u2019s status.<\/li>\n<li><span style=\"color: #993300\">mutephone<\/span>: Mutes the victim\u2019s phone<\/li>\n<li><span style=\"color: #993300\">normalphone<\/span>: Restores the phone to its normal state.<\/li>\n<li><span style=\"color: #993300\">fullinformation<\/span>: Sends complete device information, including text messages, call history, contacts, and installed apps information<\/li>\n<li><span style=\"color: #993300\">AppList<\/span>: Sends a list of apps installed on the phone.<\/li>\n<li>\u00a0\u00a0\u00a0 screenshot: Captures screenshot of the current activity screen and sends it to the server.<\/li>\n<li>\u00a0<span style=\"color: #993300\">putdomain<\/span>: Changes the malware&#8217;s C2 server address.<\/li>\n<li>\u00a0<span style=\"color: #993300\">hideicon<\/span>: Hides the malware\u2019s application icon for stealth.<\/li>\n<li>\u00a0<span style=\"color: #993300\">unhideicon<\/span>: Restores the application icon to its normal state.<\/li>\n<li>\u00a0<span style=\"color: #993300\">changeicon<\/span>: Alters the application icon to prevent detection by the user.<\/li>\n<li>\u00a0<span style=\"color: #993300\">BankInformation<\/span>: Extracts sensitive bank-related messages and account information from the victim\u2019s device.<\/li>\n<li>\u00a0<span style=\"color: #993300\">CardNumbers<\/span>: Extracts the victim&#8217;s bank card numbers from available data.<\/li>\n<li>\u00a0<span style=\"color: #993300\">lastmessage<\/span>: Retrieves the last sent and received text messages.<\/li>\n<li>\u00a0<span style=\"color: #993300\">BankSMS<\/span>: Extracts bank-related SMS messages from the inbox.<\/li>\n<li>\u00a0<span style=\"color: #993300\">inboxSMS<\/span>: Retrieves all incoming SMS messages.<\/li>\n<li>\u00a0<span style=\"color: #993300\">outboxSMS<\/span>: Retrieves all sent SMS messages.<\/li>\n<li>\u00a0<span style=\"color: #993300\">getphones<\/span>: Retrieves the list of phone numbers stored on the device.<\/li>\n<li>\u00a0<span style=\"color: #993300\">updatesimcard<\/span>: Gathers SIM card information, such as IMSI and ICCID numbers.<\/li>\n<li>\u00a0<span style=\"color: #993300\">send_default<\/span>: Sends SMS from the phone\u2019s default number.<\/li>\n<li>\u00a0<span style=\"color: #993300\">send_solt<\/span>: Sends SMS from the second SIM card on dual SIM devices.<\/li>\n<li>\u00a0<span style=\"color: #993300\">send_contacts<\/span>: Sends the victim\u2019s contact list to the server.<\/li>\n<li>\u00a0<span style=\"color: #993300\">offlinemodeon<\/span>: Activates the malware\u2019s offline mode, allowing it to send data via SMS.<\/li>\n<li>\u00a0<span style=\"color: #993300\">offlinemodeoff<\/span>: Deactivates offline mode.<\/li>\n<li>\u00a0<span style=\"color: #993300\">detect_saderat<\/span>: Detects SMS messages from Saderat Bank.<\/li>\n<li><span style=\"color: #993300\">detect_target<\/span>: Detects SMS messages received from specific numbers<\/li>\n<li><span style=\"color: #993300\">detect_exchange<\/span>: Detects cryptocurrency applications installed on the phone<\/li>\n<li><span style=\"color: #993300\">runussdcode<\/span>: Runs USSD codes on the victim&#8217;s phone<\/li>\n<\/ul>\n<p>&nbsp;<\/p>\n<p>&nbsp;<\/p>\n<p><span style=\"color: #800080\"><strong>? <em>_send_bankdata Method<\/em><\/strong><\/span><\/p>\n<p>This method examines the user&#8217;s bank SMS messages and extracts information such as account balance, bank name, account number, and cut number using the getvvvvvvvvv2_ method and sends it to its server along with other user-related information (such as the victim&#8217;s phone model, phone ID, user&#8217;s phone operator, malware icon status, and screen status). In the getvvvvvvvvv2_ method, as shown in the image below, the list of received SMS messages is first extracted and then each user&#8217;s SMS message is examined to find bank messages, along with the text and sender number of the SMS. Next, it detects the bank name from the SMS text and sender number using the detect_bankname_ method. The name of the bank sending the message is obtained using a series of keywords and Regex. The malware then extracts the account balance from bank SMS messages using the bank_findbalance_ method, such that if the SMS text contains phrases such as \u201cbalance\u201d, it identifies the amount followed by this as the account balance. The detect_bankaccountnumber_ method also extracts the account number or card number from the SMS text, if the SMS text contains phrases such as \u201caccount\u201d, \u201cwithdrawal from\u201d or \u201ccard\u201d, the malware tries to extract the number followed by these phrases. Finally, the account and balance information is sent to the send_bankdata_ method.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter wp-image-4368 \" src=\"http:\/\/threats.amnpardaz.com\/wp-content\/uploads\/sites\/2\/2025\/02\/3-\u0645\u062a\u062f-_send_bankdata.png\" alt=\"\u0645\u062a\u062f _send_bankdata\" width=\"978\" height=\"525\" \/><\/p>\n<p>&nbsp;<\/p>\n<p><span style=\"color: #800080\"><strong>\u00a0? <em>sendUssdRequest Method<\/em><\/strong><\/span><\/p>\n<p>The sendUssdRequest method allows the malware to send USSD requests using the TelephonyManager class. These codes, such as #123* or #1*140*, are sent to the mobile operator, and the response is captured by the onReceiveUssdResponse method. The response, which may include account balances or other operator-related information, is then forwarded to the C2 server.<\/p>\n<p>The malware uses this method to determine if an active SIM card is present and, if so, sends the USSD response to the attacker\u2019s desired number via the vvvvvvvv4_ method.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"wp-image-4369 aligncenter\" src=\"http:\/\/threats.amnpardaz.com\/wp-content\/uploads\/sites\/2\/2025\/02\/4-\u0645\u062a\u062f-sendUssdRequest.png\" alt=\"\u0645\u062a\u062f sendUssdRequest\" width=\"887\" height=\"254\" \/><\/p>\n<h2>How to Deal with and Clean the System<\/h2>\n<p>To ensure that a device is free from this malware, install the <a href=\"https:\/\/padvish.com\/en-us\/avapk\"><span style=\"color: #3366ff\">Padvish Antivirus for android<\/span><\/a>, ensure its database is up-to-date, and perform a full device scan to detect and remove the malware.<\/p>\n<h3>How to Prevent Mobile Phone Infections<\/h3>\n<ul>\n<li>To protect your device from infection by this or similar malware, adhere to the following best practices:<\/li>\n<li>Legitimate judicial or government communication will never come from personal numbers or through untrustworthy channels such as Telegram, WhatsApp, or other social networks. Additionally, official notifications will not contain links for payments.<\/li>\n<li>Always download applications from trusted Android marketplaces, and avoid unofficial versions of apps, as they may contain malicious code.<\/li>\n<li>There is no need to pay any fees to view electronic notices or justice shares.<\/li>\n<li>Always check the permissions requested by an app before installing it.<\/li>\n<li>Do not use modified or unofficial versions of apps.<\/li>\n<\/ul>\n","protected":false},"excerpt":{"rendered":"<p>Overview Type: Trojan Destruction Degree: Medium Prevalence: Medium &nbsp; Malware Names (Padvish) Trojan.Android.SmsSpy.DET (Kaspersky) HEUR:Trojan.AndroidOS.Hiddapp.ay (BitDefenderFalx) Android.Trojan.SpyAgent.OK (ESET) A Variant Of Android\/Spy.Agent.DET &nbsp; What is a Trojan? A Trojan is a type of malware that masquerades as legitimate software, presenting itself as functional and benign. However, once executed, it performs malicious actions that can cause&hellip;<\/p>\n","protected":false},"author":27,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[2],"tags":[89,90],"class_list":["post-1613","post","type-post","status-publish","format-standard","hentry","category-trojan","tag-smsspy","tag-trojan-android-smsspy-det"],"_links":{"self":[{"href":"https:\/\/threats.amnpardaz.com\/en\/wp-json\/wp\/v2\/posts\/1613","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/threats.amnpardaz.com\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/threats.amnpardaz.com\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/threats.amnpardaz.com\/en\/wp-json\/wp\/v2\/users\/27"}],"replies":[{"embeddable":true,"href":"https:\/\/threats.amnpardaz.com\/en\/wp-json\/wp\/v2\/comments?post=1613"}],"version-history":[{"count":3,"href":"https:\/\/threats.amnpardaz.com\/en\/wp-json\/wp\/v2\/posts\/1613\/revisions"}],"predecessor-version":[{"id":1616,"href":"https:\/\/threats.amnpardaz.com\/en\/wp-json\/wp\/v2\/posts\/1613\/revisions\/1616"}],"wp:attachment":[{"href":"https:\/\/threats.amnpardaz.com\/en\/wp-json\/wp\/v2\/media?parent=1613"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/threats.amnpardaz.com\/en\/wp-json\/wp\/v2\/categories?post=1613"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/threats.amnpardaz.com\/en\/wp-json\/wp\/v2\/tags?post=1613"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}