SHA1: 630da09c6ab6df504338e1525aabeabcf686b3a4
It is a multifunctional Trojan for Android. The examined sample looks as follows:
/data/system/.loki/lokisdk.jar
The Trojan is downloaded using the liblokih.so library that Android.Loki.3 incorporates into the system_server process. As a result, Android.Loki.1.origin gets the system privileges. Installed applications interact with the service by using the ServiceConnection and IBinder methods.
Android.Loki.1.origin is a service that can perform the following functions:
- Downloads applications from Google Play specifying a referrer
- Downloads and deletes applications
- Enables and disables applications and their components
- Kills processes
- Displays notifications
- Registers an application as the Accessibility Service application
- Updates its components and downloads plug-ins from the server