Malicious Android App Signs Users up to Premium SMS Services
This content has been archived
This article no longer conforms to NHS Digital's standards for cyber alerts, and may contain outdated or inaccurate information. Use of this information contained in this page is at your own risk
Summary
Threat details
Downloaded over 5000 times,Swift Cleaner will collect device and user information when first installed before sending this as an SMS message to a hardcoded number to initiate command and control (C2) communications. The C2 server will then execute click ad and URL forwarding routines.
The click ad routine will instruct the malware to execute a Wireless Application Protocol (WAP) task to collect information on the user's service provider. This is then sent back to the C2 server, where it is used to enrol the user in multiple paid SMS services.
Remediation steps
Last edited: 17 February 2020 12:47 pm