FireEye has uncovered and helped weaken one of the largest advanced mobile botnets to date. The botnet, which we are dubbing “MisoSMS,” has been used in at least 64 spyware campaigns, stealing text messages and emailing them to cybercriminals in China.
MisoSMS infects Android systems by deploying a class of malicious Android apps. The mobile malware masquerades as an Android settings app used for administrative tasks. When executed, it secretly steals the user’s personal SMS messages and emails them to a command-and-control (CnC) infrastructure hosted in China. FireEye Mobile Threat Prevention platform detects this class of malware as “Android.Spyware.MisoSMS.”
Here are some highlights of MisoSMS:
- We discovered 64 mobile botnet campaigns that belong to the MisoSMS malware family.
- Each of the campaigns leverage Web mail as its (CnC) infrastructure.
- The CnC infrastructure comprises more than 450 unique malicious email accounts.
- FireEye has been working with the community to take down the CnC infrastructure.
- The majority of the devices infected are in Korea, which leads us to believe that this threat is active and prevalent in that region.
- The attackers logged in from Korea and mainland China, among other locations, to periodically read the stolen SMS messages.
MisoSMS is active and widespread in Korea, and we are working with Korean law enforcement and the Chinese Web mail vendor to mitigate this threat. This threat highlights the need for greater cross-country and cross-organizational efforts to take down large malicious campaigns.
At the time of of this blog post, all of the reported malicious email accounts have been deactivated and we have not noticed any new email addresses getting registered by the attacker. FireEye Labs will closely monitor this threat and continue working with relevant authorities to mitigate it.

