A malicious program for Android designed to steal confidential information from handhelds in China and to install other malware onto the compromised devices.
Installs hidden component
When launched, Android.SmsSend.1404.origin checks if the malware Android.SmsBot.146.origin ( com.android.trogoogle package) is present in the system. If not, it will attempt to install the program for which it will prompt the user to install a critical update.
Steal personal information
The program imitates the authentication process by requesting a login and password, however, regardless of the input information, the user will be prompted to register by providing their personal identification number and name. The gathered confidential information is forwarded to criminals.
To facilitate its spreading, Android.SmsBot.146. origin sends short messages containing its download link to all the contacts found in the phone book.