The Trojan runs in the background and has no user interface. It installs other applications from a certain site. Such applications are tracked in an internal database. New data is downloaded from a server in JSON format.
Geographical distribution of attacks by the Trojan.AndroidOS.Roversa family
Top 10 countries with most attacked users (% of total attacks)
* Percentage among all unique Kaspersky users worldwide attacked by this malware