Content

SymbOS/Mopofeli.a!sis

Type
Trojan
SubType
Spyware
Discovery Date
01/02/2007
Length
Minimum DAT
4930 (01/02/2007)
Updated DAT
4930 (01/02/2007)
Minimum Engine
5.1.00
Description Added
01/02/2007
Description Modified
02/26/2007 11:52 AM (PT)
Risk Assessment
Corporate User
Low
Home User
Low

Tab Navigation

Characteristics

SymbOS/Mopofeli.A is a commercial application used for monitoring text messages. It is distributed in a sis file named "PKERNEL.SIS".

The malware installs under the name "pKernel".

Text displayed during installation.

Fig 1 – Text displayed during installation.

A user who purchases SymbOS/Mopofeli.A must know the IMEI of the device they wish to monitor.

The user must also provide a mobile number which is to receive the forwarded SMS messages.

The user must send an SMS message containing a start message to the target phone to begin receiving forwarded messages. Similarly an SMS message containing a stop message must be sent to end the forwarding of messages.

SymbOS/Mopofeli.A sends the contents of incoming and outgoing SMS messages to a preset number by SMS.

Symptoms

SymbOS/Mopofeli.A steals the following information:

  • The contents of incoming and outgoing SMS messages.

The stolen message content is forwarded to a predetermined phone number.

Method of Infection

Removal

Variants

Variants

    N/A

All Information

Overview -

SymbOS/Mopofeli.A is a spyware application. This malware monitors incoming and outgoing SMS messages. SymbOS/Mopofeli.A forwards these messages to a predetermined phone number.

Characteristics

Characteristics -

SymbOS/Mopofeli.A is a commercial application used for monitoring text messages. It is distributed in a sis file named "PKERNEL.SIS".

The malware installs under the name "pKernel".

Text displayed during installation.

Fig 1 – Text displayed during installation.

A user who purchases SymbOS/Mopofeli.A must know the IMEI of the device they wish to monitor.

The user must also provide a mobile number which is to receive the forwarded SMS messages.

The user must send an SMS message containing a start message to the target phone to begin receiving forwarded messages. Similarly an SMS message containing a stop message must be sent to end the forwarding of messages.

SymbOS/Mopofeli.A sends the contents of incoming and outgoing SMS messages to a preset number by SMS.

Symptoms

Symptoms -

SymbOS/Mopofeli.A steals the following information:

  • The contents of incoming and outgoing SMS messages.

The stolen message content is forwarded to a predetermined phone number.

Method of Infection

Method of Infection -

Removal -

Removal -

Variants

Variants -

    N/A