Backdoor.AndroidOS.Torec.a is a variation of the popular Orbot Tor client. Trojan uses the anonymous Tor network built on a network of proxy servers. Trojan can receive commands from the C&C that include intercepting incoming SMSs and theft of outgoing SMSs. Trojan doesn’t pass itself off as Orbot it simply uses the functionality of the client. The Trojan can also display anonymous sites in the.onion domain zone that can only be accessed in Tor.”]
Source: https://securelist.com/the-first-tor-trojan-for-android/58528/