If the user clicks on the link, a file named mms.apk, containing Opfake.a, is automatically loaded onto the smartphone or tablet. Then again, the user has to be a bit of an idiot and users run the downloaded program. If that happens, the botnet's command and control server can instruct the Trojan to send out the following message to all the contacts in the victim’s address book:
You have a new MMS message, download at -
http://otkroi.net/12
If the people who get this message follow the link , they'll automatically loads Obad.a under the names of mms.apk or mmska.apk. And, if they foolishly run these programs, they'll get a case of Obad.a.
All of this requires mindless clicking by users to work, but guess what?
There are a lot of idiots out there.Click to expand...