Android trojan spreads through Cutwail spam botnet

An Android trojan is being spread through one of the world's largest spam botnets.

According to an analysis posted last month by Brett Stone-Gross, a senior security researcher at Dell SecureWorks Counter Threat Unit, the trojan, called Stels, is delivered through emails sent by the Cutwail spam botnet.

The phishing emails lure users into clicking malicious links that appear to be an Adobe Flash Player update.

Stels is capable of stealing mobile users' contact lists and sending or intercepting text messages. It can also uninstall applications, make phone calls, including those to premium numbers, and deploy additional malware.

Though Stels cannot "root" Android devices, it can operate on nearly all versions of the mobile operating system, Stone-Gross said.

Sign up to our newsletters

More in News

Three LulzSec members plead guilty in London

Ryan Ackroyd, 26; Jake Davis, 20; and Mustafa al-Bassam, 18, who was not named until now because of his age, all admitted their involvement in the hacktivist gang's attack spree.

WordPress tightens security with two-factor authentication

The new feature is immediately available for users and "secret" codes can be accessed via SMS or through the Google Authenticator app.

Microsoft fixes three "critical" flaws with Patch Tuesday release

The biggies are two vulnerabilities in Internet Explorer and a single weakness in Remote Desktop Connection.