#KevDroid
Malware/Tool
2018-04-02 • Fake AV Investigation Unearths KevDroid, New Android Malware
KevDroid is an Android remote-administration tool and spyware family named from “Kevin” artifacts found in its code. Two analyzed variants steal contacts, SMS messages, phone history, and other device information, record calls using code derived from an open-source project, and send collected data to a command-and-control server through HTTP POST requests. One variant exploits CVE-2015-3636 to obtain root access. Related activity used trojanized Bitcoin Ticker Widget and PyeongChang Winter Games applications as downloaders, while another sample masqueraded as a Naver antivirus application. Attribution to Group 123 remained unconfirmed in the originating analysis.
-
2
Tagged Reports
-
2
Unique Authors
-
4
Active Days