A Trojan for Android devices. It was distributed via Google Play under the guise of an official application on the “Eldorado” trade network. New modifications of this malicious application can be spread as other software.
Once lunched, Android.Click.265.origin opens the “Eldorado” official online store page in WebView. It allows a user to work normally with the online store. However, the Trojan can load websites with premium content depending on the traffic distribution system (TDS) parameters of the C&C server. Android.Click.265.origin then automatically clicks the confirmation button to subscribe to a service. This button is placed on the website with the premium content. As a result, a victim’s mobile number is charged for using a high-priced service every day.
The Trojan also shows advertisements.