sha1:
- b58fafa093f6bb42a0bbb28b71db5c8a72d55f6c
Description
An Android data stealer disguised as a Tron wallet bruteforcer.
Operating routine
When launched, it launches a service that performs the following functions:
- Removes the application icon and entry from the application list
-
Requests permissions
android.settings.MANAGE_APP_ALL_FILES_ACCESS_PERMISSION android.permission.CAMERA
- Accesses ipinfo[.]io for location information (IP address, network host name, city, region, country, coordinates, index, time zone)
- Takes a photo through the front camera
- Sends system information, including error logs and images from the DCIM/Camera and Pictures/Screenshots directories, to Telegram bots whose identifiers are hardcoded in the body of the trojan.