Aug12 |
11:56 am (UTC-7) | by
Mark Balanza (Threats Analyst) |
Last week, we reported on ANDROIDOS_NICKISPY.A and ANDROIDOS_NICKISPY.B, Android malware that recorded phone calls made from infected devices then sent stolen information to a remote site.
This week, we saw another Android malware with the same code structure as ANDROIDOS_NICKISPY.A. Like the latter, this does not display an icon and executes similar routines, save for some modifications.
Detected by Trend Micro products as ANDROIDOS_NICKISPY.C, it uses the following services:
- MainService
- AlarmService
- SocketService
- GpsService
- CallRecordService
- CallLogService
- UploadService
- SmsService
- ContactService
- SmsControllerService
- CommandExecutorService
- RegisterService
- CallsListenerService
- KeyguardLockService
- ScreenService
- ManualLocalService
- SyncContactService
- LocationService
- EnvRecordService
This malware comes in the guise of Google+, Google’s most recent foray into the social networking scene, in an attempt to hide from affected users. All the above-mentioned services use the Google+ icon. The app itself is installed using the name, Google++.
![]() |
![]() |
ANDROIDOS_NICKISPY.C is capable of collecting data such as text messages, call logs, and GPS location from infected devices, which it then uploads to a certain URL through port 2018.
It is also capable of receiving commands via text messages. To do so, however, it requires the sender to use the predefined “controller” number from the malware’s configuration file to send a message as well as to enter a password to execute the command.
Listening In
Like other ANDROIDOS_NICKISPY variants, ANDROIDOS_NICKISPY.C also has the capability to record phone calls made from infected devices. What makes this particular variant different is that it has the capability to automatically answer incoming calls.
![]() |
The code suggests that the following criteria must be met before the malware can answer a phone call:
- The call must come from the number on the “controller” tag from its configuration file.
- The phone screen must be turned off.
Before answering the call, it puts the phone on silent mode to prevent the affected user from hearing it. It also hides the dial pad and sets the current screen to display the home page. During testing, after the malware answered the phone, the screen went blank.
![]() |
![]() |
From the looks of it, the developer of this app went for the more real-time kind of eavesdropping as well, apart from the one ANDROIDOS_NICKISPY.A used, which involved recording calls.
The “auto-answering” function of this malicious Android app works only on Android 2.2 and below since the MODIFY_PHONE_STATE permission was disabled in Android 2.3.
For ways to keep your Android-based devices secure, check out our e-book, “5 Simple Steps to Secure Your Android-Based Smartphones.”
Additional analysis by Julius Dizon and Kervin Alintanahin
Related blog entries here:
Share this article |
|
88 Responses to “Android Malware Eavesdrops on Users, Uses Google+ as Disguise”
Trackbacks
- New Android Spyware Threat Disguises Itself as Google+ App | Teknik Enshus
- New Android Spyware Threat Disguises Itself as Google+ App | Tmobile News
- New Android Spyware Threat Disguises Itself as Google+ App | Android Blog
- New Android Spyware Threat Disguises Itself as Google+ App | galaxytb.com
- New Android Spyware Threat Disguises Itself as Google+ App | Hottest Gadget
- New Android Malware Hides as Google+ App, Answers Calls for You | Droid Universe
- iPhone Games » New Android Malware Hides as Google+ App, Answers Calls for You
- New Android Spyware Threat Disguises Itself as Google+ App | Electronic Gadgets
- TrendMicro Malware Blog August 15, 2011
- New Android Malware Hides as Google+ App, Answers Calls for You | TechDiem.com
- New Android Malware Hides as Google+ App, Answers Calls for You | Android News Center
- Nuevo Malware oculto en una App para Google+. | HosterBlog
- New Android Malware Hides as Google+ App, Answers Calls for You | Krantenkoppen Tech
- Android Malware Records Calls, Masks as Google+
- Android Malware Records Calls, Masks as Google+
- Malware que se disfarça de Google+ » Shelter-Tech
- New Android Malware Hides as Google+ App, Answers Calls for You | Android Tablets News
- New Android Spyware Threat Disguises Itself as Google+ App | Gadget Information
- New Android Malware Hides as Google+ App, Answers Calls for You | Market To Phones
- New Android Malware Hides as Google+ App, Answers Calls for You
- New Android Malware Hides as Google+ App, Answers Requires You | Modern Techie
- New Android Spyware Threat Disguises Itself as Google+ App | Techost.info
- New Android Malware Disguises Itself As Google+, Records Phone Calls, Call Logs And Text Messages | Redmond Pie
- Android Malware Disguised as Google+ App | Hubze Blog
- New Android Malware Hides as Google+ App, Answers Calls for You | iMobile One
- New Android Malware Hides as Google+ App, Answers Calls for You | Bitmag
- New Android Spyware Threat Disguises Itself as Google+ App - Latest Info & News
- Web and Technology » Blog Archive » New Android Spyware Threat Disguises Itself as Google+ App
- New Android Spyware Threat Disguises Itself as Google+ App | Gadget News Site
- New Android Spyware Threat Disguises Itself as Google+ App - Frenmobile.info
- New Android Malware Hides as Google+ App, Answers Calls for You « Whella : All About Mobile
- New Android Spyware Threat Disguises Itself as Google+ App | End User Personal Desktop
- New Android Spyware Threat Disguises Itself as Google+ App | All around Gadget
- New Android Spyware Threat Disguises Itself as Google+ App | Agregatenews.info
- New Android Spyware Threat Disguises Itself as Google+ App | Latest Gadgets News
- New Android Spyware Threat Disguises Itself as Google+ App | Simplyhotnews.info
- Android malware answers calls, eavesdrops on users | RXTX
- New Android Spyware Threat Disguises Itself as Google+ App | Gadget Geek Gifts
- Malware ตัวใหม่ของ Android แอบอยู่ในแอพ Google+
- New Android Malware Hides as Google+ App, Answers Calls for You | Push to Talk
- New Android Malware Disguises Itself As Google+, Records Phone Calls, Call Logs And Text Messages
- 一个新Android恶意软件:伪装成Google+ App | 牛牛网
- Android 竊聽風雲 | PK Information Security
- New Android Malware Disguises Itself As Google+, Records Phone Calls, Call Logs And Text Messages | iPhone5 news, updates, articles, apps
- מתחזים לגוגל פלוס | Newsgeek
- New Android Malware Hides as Google+ App, Answers Calls for You | Product Launch Buzz
- Android malware answers calls, eavesdrops on users | Just Got Hacked
- Google++ ismi ile gizlenen Malware Aramaları ve Mesajları kayıt ediyor - SiberElma
- New Android Malware Hides as Google+ App, Answers Calls for You » FaceiZ
- New Android Malware Hides as Google+ App, Answers Calls for You | 0code.net - Sharing Everything
- Detectado nuevo troyano en Android capaz de responder a las llamadas | eWEEK Europe España
- New Android Malware Disguises Itself As Google+, Records Phone Calls, Call Logs And Text Messages | Wherz It At Today
- Android malware masquerading as Google+ app | News Channel – Mind Processors
- Android malware masquerading as Google+ app | I Bleed Bits | Android
- Android malware masquerading as Google+ app | Android News Center
- Android malware masquerading as Google+ app | Android Tablets News
- Android malware masquerading as Google+ app
- Drošības Eksperti
- Alertan de un troyano para Android que contesta a las llamadas - Foros de Informatica - Foro de Windows 7, Foro de ayuda, Noticias de Informatica, Windows 7 y Windows Vista
- Android malware masquerading as Google+ app | Andriod
- Android malware masquerading as Google+ app | Android Blog
- Android malware masquerading as Google+ app - Tech News
- Android malware masquerading as Google+ app | BestXperiaPlay.com
- Zepley – Android malware hiding as Google+ app discovered
- Android malware masquerading as Google+ app | RegionalForward.info
- Android malware masquerading as Google+ app | RegionalForward.info
- Android malware masquerading as Google+ app | IT News Post
- ADROIDOS_NICKISPY.C, un troyano sin parangón
- Android malware masquerading as Google+ app | Source Of Drivers
- New Android malware disguises itself as Google+ App | Latest Telecom Technology News and Updates
- Alertan de un troyano para Android que contesta a las llamadas | The Inquirer ES
- Android users will have to deal with yet another blow,new Android Malware disguises itself as Google+ - Xponent 4
- Google++ : Attention danger pour Android - Android-Zone.fr | Android-Zone.fr
- Malware en Android que puede confundirse con la aplicación de Google+ | GeeksRoom
- Malware en Android que puede confundirse con la aplicación de Google+ | Tecnologia, Desarrollo Web, Posicionamiento Web SEO
- Fake App Is Fake: Google++ Hides A Trojan Inside.
- CodeAndroid Thailand : Android Developer and User Group in Thailand » Blog Archive » Trend Micro ออกมาเตือนให้ระวังแอพฯมัลแวร์ Google++
- New Android Malware Hides as Google+ App, Answers Calls for You | AndroidFools
- Spying Android Malware Hides as Google+ App | Android Blog
- Spying Android Malware Hides as Google+ App | LocatePC | Locate your stolen computer or stolen laptop - Works for both Mac and PC
- Novo Malware para Android é Capaz de Atender Chamadas | InvasaoHacking.com - Downloads, Video Aulas e Tutoriais sobre Hacker, Trojans, Keyloggers, Worms, Malwares, Virus, phishing, Exploit, Shells, Defacer, banking, carding, Hackear orkut, Hackear Msn, H
- Malware Masquerades as Google+ App | Inc. Technology
- Появи се нов Android спайуер, маскиран като Google+ приложение | Нова.бг
- Fraud Consulting Ltd – Android Malware Disguised as Google+
- In wake of Android Trojans, enterprises need Android security policy | Android Tablets
- In wake of Android Trojans, enterprises need Android security policy | Android
- Android Malware Eavesdrops on Users, Uses Google+ as Disguise | Simply Security
- ¡Cuidado! Hay un nuevo virus en Android camuflado de Google+ | soyApps.com








