Detect Date 09/29/2015
Class Trojan-SMS
Platform AndroidOS

These malicious programs send SMS messages to premium-rate short numbers without the user’s knowledge. The program configuration is stored in an encrypted JavaScript script. Notably, this malware family is widespread not only in the CIS countries (where most malware of this type is concentrated), but in other countries as well. Malicious programs of this family support a large number of premium-rate numbers in many countries.

Geographical distribution of attacks by the Trojan-SMS.AndroidOS.Stealer family


Geographical distribution of attacks during the period from 31 July 2014 to 3 August 2015

Top 10 countries with most attacked users (% of total attacks)

Country % of users attacked worldwide*
1 Russia 85.88
2 Kazakhstan 4.59
3 Ukraine 3.34
4 Belarus 1.55
5 Uzbekistan 0.80
6 Azerbaijan 0.63
7 Kyrgyzstan 0.43
8 Tajikistan 0.38
9 Germany 0.35
10 Moldova 0.19

* Percentage among all unique Kaspersky users worldwide who were attacked by this malware

Find out the statistics of the threats spreading in your region