This application is a team mangament application that showcases the members of the team. It is a malicious APK that extracts data out from the phone and sent out to an email.
- Device Location
- Phone call logs
- Access contacts
- Manage phone calls
- Send and view SMS messages
- Access photos and media on device
Once the user opens the application for the first time, it will request for necessary runtime permissions. Then a connection will be established to our email address. It gathers certain information about the device. An example of it is shown in the two screenshots below
The information exfiltrated are:
| Exfiltrated | Detailed information |
|---|---|
| Device Information | OS Version, API Level, Device Name, Device ID, Manufacturer, Model Name, Product Name and Battery Level |
| Location Information | Longitude and Latitude |
| Network Information | Network ID, SSID and BSSID, Device IP Address |
| Location Information | Longitude and Latitude |
| Call Logs | Phone Number, Call type, Call Date and Call Duration |
| SMS Messages | SMS Date, Recipient Number, SMS Type and SMS Body |
| Images | Image Content and Image File Name |
| Incoming SMS Messages | Sender’s Number and Message Body |
There is also a function that utilises SMSBroadcastReceiver() to listen for incoming SMS messages and then forwarding it to our email address. This will be identified by the android ID in the email header. It can be run in the background as well, not opening the application at all.
The email is in the format of "SMS - AndroidID", for identification of the user's phone
- Android App Studio
- ProGuard Obfuscator
- Tan Jia Ding
- Clarence Tan Jia Jun
- Lam Wei Ern
- Dylan Teo Jian Le
- Yap Jia Hao
- Marvin Wong Soon Hong
If there is a need for access into the gmail account used, kindly send an email to 2101957@sit.singaporetech.edu.sg



