Intelligence View
Android Trojan Roots Devices, Steals Photos and Chrome's Database
An Android malware family identified as Trojan-Banker.AndroidOS.Tordow.a (Tordow in this article) has been making victims left and right, infecting smartphones, rooting the users' devices, and then stealing sensitive information and…
Signs of this malware family appeared in February 2016, when first infections started popping up, mainly due to users downloading Android apps from unofficial third-party app stores.
Tordow distributed via clones of popular Android apps
Kaspersky Lab malware analyst Anton Kivva says that most of the apps that spread Tordow are clones of more popular Android apps such as VKontakte, DrugVokrug, Pokemon Go, Telegram, Odnoklassniki or Subway Surf.
Crooks take these apps, unpack their source code, add their own malicious code inside, repackage them, and upload the newly created clones to third-party app stores.
Users that download these apps, unwittingly triggered the malicious...