Skip to main content

Malicious Android App Signs Users up to Premium SMS Services

A malicious app, written in the Kotlin open-source language, has been observed on the Google Play Store. Swift Cleaner appears to be a utility tool for cleaning and optimising Android devices, but has information stealing and remote execution capabilities. It can also sign users up for premium SMS subscription services.
Report a cyber attack: call 0300 303 5222 or email [email protected]

This content has been archived

This article no longer conforms to NHS Digital's standards for cyber alerts, and may contain outdated or inaccurate information. Use of this information contained in this page is at your own risk

Summary

A malicious app, written in the Kotlin open-source language, has been observed on the Google Play Store. Swift Cleaner appears to be a utility tool for cleaning and optimising Android devices, but has information stealing and remote execution capabilities. It can also sign users up for premium SMS subscription services.

Threat details

Downloaded over 5000 times,Swift Cleaner will collect device and user information when first installed before sending this as an SMS message to a hardcoded number to initiate command and control (C2) communications. The C2 server will then execute click ad and URL forwarding routines.

The click ad routine will instruct the malware to execute a Wireless Application Protocol (WAP) task to collect information on the user's service provider. This is then sent back to the C2 server, where it is used to enrol the user in multiple paid SMS services.


Remediation steps

Type Step
  • Users are advised to only download legitimate and necessary applications, or should consider implementing a centrally-approved list of applications.
  • Users should ensure their mobile devices are full update

Last edited: 17 February 2020 12:47 pm