GTC Malware Library Search

MobiStealth
Affected Operating Systems: Android, BlackBerry
Aliases:
Discovery Date: 2010-01-13
Overview: MobiStealth is a spyware application for Android and BlackBerry platforms
Detailed Information: MobiStealth is a spyware application that currently runs on Android and BlackBerry devices.  MobiStealth has the ability to completely hide itself from detection by the intended user.  MobiStealth has the following capabilities:
  • Call Recording
  • Call History
  • Call Duration
  • On Demand Surround Recording
  • Location History
  • On Demand Location Information
  • Alternative Location Retrieval Method
  • Email Logging
  • Web History
  • Bookmarks
  • Picture Logging
  • Video Logging
  • Contact Details
  • Text Message / SMS Logging
  • Reverse Phone Lookup
  • SIM Change Notification (Only Applicable to GSM Phones)
  • Encrypted Communication
  • Phone Wipe

For Android, MobiStealth arrives as mobistealth.apk and installs on the device as EmailClient.  MobiStealth hides itself from detection by the intended target in that no application icon is visible in the application drawer on the device.  However, viewing the list of installed applications through Settings > Applications > Manage applications will reveal the existence of the EmailClient application. For BlackBerry, MobiStealth arrives as .zip file that contains the following files:

  • EmailClient.cod
  • EmailClient-1.cod
  • mmv2.jad

Once installed, MobiStealth exists on the device as EmailClient and does not offer an application icon as it is completely hidden from the user. MobiStealth can only be installed on a target device with physical access. Detection and Removal: Detected and removed with SMobile VirusGuard virus definitions from 2010-01-13