Threat Research

Android/DroidKungFu: attacking from a mobile device?

The Android malware DroidKungFu reports back to the following URLs: http://[REMOVED] http://[REMOVED] http://[REMOVED] A whois on the corresponding IP address replies with the following most peculiar information: it looks like the IP address belongs to a mobile device (either a phone, or a tablet, or a computer with a 2G/3G connection...) of a well-known Chinese operator. Of course, we have immediately notified this operator. This is rather...

By Axelle ApvrilleJune 16, 2011