Blog | G5 Cyber Security

Pre-installed auto installer threat found on Android mobile devices in Germany

Gigaset mobile devices contain an Update app which is a pre-installed system app infected with Android/PUP.Riskware. This app is not only the mobile devices system updater, but also an Auto Installer known as Android.Autoins.Redstone.ui. The Update app installs three versions of Android/Trojan.DownloaderAgent.WAGD. It can in addition send malicious SMS messages to further spread the infection. The downloading and installation of this SMS Agent is due to Android.AgentYHN4 on their mobile devices.”]

Source: https://blog.malwarebytes.com/android/2021/04/pre-installed-auto-installer-threat-found-on-android-mobile-devices-in-germany/

Exit mobile version