{"id":9892,"date":"2011-07-11T18:58:21","date_gmt":"2011-07-12T01:58:21","guid":{"rendered":"http:\/\/blogs.mcafee.com\/?p=9892"},"modified":"2025-05-29T03:40:38","modified_gmt":"2025-05-29T10:40:38","slug":"dissecting-zeus-for-android-or-is-it-just-an-sms-spyware","status":"publish","type":"post","link":"https:\/\/www.mcafee.com\/blogs\/other-blogs\/mcafee-labs\/dissecting-zeus-for-android-or-is-it-just-an-sms-spyware\/","title":{"rendered":"Dissecting Zeus for Android (or Is It Just SMS Spyware?)"},"content":{"rendered":"<p>Zeus, also known as ZBot, is one of best-known malware in the industry. The main purpose of this malware is to steal banking credentials, allowing attackers to commit electronic fraud. Until 2010, Zeus existed only for personal computers since this platform was (and still is) the principal medium for electronic transactions. However, due to the increasing popularity of mobile devices and the fact that many companies now allow the sending of mTANs (Mobile Transaction Authentication Number) via SMS as a second factor of authentication, in September of 2010 a new variant of Zeus\u00a0was discovered. This one targets mobile devices (Symbian, Blackberry, and Windows Mobile) and will intercept SMS\u2019s sent to the user by the bank and forward the captured mTANs to a remote server to defeat the SMS-based banking two-factor authentication.<\/p>\n<p>\u201cLately there\u2019s been an active discussion on technical forums regarding Zeus targeting Android users\u201d said Axelle Apvrille of Fortinet, which, along with other security companies like F-Secure, s21sec, and Kaspersky, discovered a Zeus version for one of the most prevalent and popular operating systems for smartphones: Zitmo for Android. Apparently <a title=\"the sample\" href=\"https:\/\/nakedsecurity.sophos.com\/2011\/07\/09\/android-malware-spies-sms-messages-zeus-family\/\" target=\"_blank\" rel=\"noopener noreferrer\">the sample <\/a>\u201cwas served to devices running the Google Android OS by a web server that was configured to deliver Zbot malware to multiple platforms.&#8221;<\/p>\n<p>Let\u2019s take a look to this application to figure out whether it\u2019s related in some way to the Zeus family.\u00a0At a first sight, the malicious application will try to impersonate the security application, Rapport, which tries to prevent man-in-the-browser malware and man-in-the-middle attacks. In fact, the icon is very similar to the official logo of Trusteer:<\/p>\n<p><a href=\"https:\/\/www.mcafee.com\/blogs\/wp-content\/uploads\/2011\/07\/fake-vs-real.png\"><img loading=\"lazy\" decoding=\"async\" class=\"size-full wp-image-9896 aligncenter\" src=\"https:\/\/www.mcafee.com\/blogs\/wp-content\/uploads\/2011\/07\/fake-vs-real.png\" alt=\"\" width=\"306\" height=\"155\" srcset=\"https:\/\/www.mcafee.com\/blogs\/wp-content\/uploads\/2011\/07\/fake-vs-real.png 306w, https:\/\/www.mcafee.com\/blogs\/wp-content\/uploads\/2011\/07\/fake-vs-real-300x151.png 300w\" sizes=\"auto, (max-width: 306px) 100vw, 306px\" \/><\/a><\/p>\n<p>But before the application is installed, Android will always show the permissions required by the application to be executed in the device. In this case, the permissions are RECEIVE_SMS, INTERNET, and READ_PHONE_STATE, which are not suspicious in this case because the application is running a phishing attack while posing as a security application that &#8220;must receive&#8221; an SMS second-factor authentication. According to the Android Manifest found inside the original apk file, the application is composed of an Activity (that is going to be executed once the user double-clicks the fake icon), a service (which will run in the background without the user&#8217;s knowledge), and a class named \u201cSmsReceiver,\u201d which execute every time the user receives an SMS:<\/p>\n<p><a href=\"https:\/\/www.mcafee.com\/blogs\/wp-content\/uploads\/2011\/07\/manifest.png\"><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-full wp-image-9897\" src=\"https:\/\/www.mcafee.com\/blogs\/wp-content\/uploads\/2011\/07\/manifest.png\" alt=\"\" width=\"628\" height=\"372\" srcset=\"https:\/\/www.mcafee.com\/blogs\/wp-content\/uploads\/2011\/07\/manifest.png 628w, https:\/\/www.mcafee.com\/blogs\/wp-content\/uploads\/2011\/07\/manifest-300x177.png 300w\" sizes=\"auto, (max-width: 628px) 100vw, 628px\" \/><\/a><\/p>\n<p>The activation will display a fake user interface acting as the security application <a title=\"Trusteer Rapport\" href=\"http:\/\/www.trusteer.com\/product\/trusteer-rapport\" target=\"_blank\" rel=\"noopener noreferrer\">Trusteer Rapport<\/a> showing the user an \u201cactivation key\u201d that should be used on the bank website, but in fact the number displayed is the phone&#8217;s International Mobile Equipment Identity separated by a hyphen (in this example the number displayed is 0 because the application was executed on an emulator):<\/p>\n<p><a href=\"https:\/\/www.mcafee.com\/blogs\/wp-content\/uploads\/2011\/07\/application-executed.png\"><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-full wp-image-9898\" src=\"https:\/\/www.mcafee.com\/blogs\/wp-content\/uploads\/2011\/07\/application-executed.png\" alt=\"\" width=\"490\" height=\"297\" srcset=\"https:\/\/www.mcafee.com\/blogs\/wp-content\/uploads\/2011\/07\/application-executed.png 490w, https:\/\/www.mcafee.com\/blogs\/wp-content\/uploads\/2011\/07\/application-executed-300x181.png 300w\" sizes=\"auto, (max-width: 490px) 100vw, 490px\" \/><\/a><\/p>\n<p>Once the application is installed, the code inside SmsReciver will run every time the user receives an SMS. This code passes the captured SMS to the service \u201cMainService,\u201d which starts a thread to collect the originating address (sender) and the message body of each SMS and stores that information in a specific structure attribute\/value pair that is commonly used to transfer data via <a title=\"HTTP\" href=\"http:\/\/www.faqs.org\/rfcs\/rfc2616.html\" target=\"_blank\" rel=\"noopener noreferrer\">HTTP:<\/a><\/p>\n<p><a href=\"https:\/\/www.mcafee.com\/blogs\/wp-content\/uploads\/2011\/07\/collecting-sms-information.png\"><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-full wp-image-9900\" src=\"https:\/\/www.mcafee.com\/blogs\/wp-content\/uploads\/2011\/07\/collecting-sms-information.png\" alt=\"\" width=\"602\" height=\"258\" srcset=\"https:\/\/www.mcafee.com\/blogs\/wp-content\/uploads\/2011\/07\/collecting-sms-information.png 602w, https:\/\/www.mcafee.com\/blogs\/wp-content\/uploads\/2011\/07\/collecting-sms-information-300x128.png 300w\" sizes=\"auto, (max-width: 602px) 100vw, 602px\" \/><\/a><\/p>\n<p>Once the sender and the body of the message is collected, the IMEI of the device will be collected as well and all the information will be sent to a remote server using a JSON object using a POST request method:<\/p>\n<p><a href=\"https:\/\/www.mcafee.com\/blogs\/wp-content\/uploads\/2011\/07\/post-method.png\"><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-full wp-image-9901\" src=\"https:\/\/www.mcafee.com\/blogs\/wp-content\/uploads\/2011\/07\/post-method.png\" alt=\"\" width=\"677\" height=\"95\" srcset=\"https:\/\/www.mcafee.com\/blogs\/wp-content\/uploads\/2011\/07\/post-method.png 677w, https:\/\/www.mcafee.com\/blogs\/wp-content\/uploads\/2011\/07\/post-method-300x42.png 300w\" sizes=\"auto, (max-width: 677px) 100vw, 677px\" \/><\/a><\/p>\n<h2>The Elements Behind the Spyware<\/h2>\n<p>The key question is whether this malware is the Zitmo version for Android. From our analysis, the sample is probably only an SMS spyware. Here&#8217;s why:<\/p>\n<ul>\n<li>\u00a0In general, this malware is not sophisticated (compared with other Android malicious code seen in the wild like ADRD) because it will only intercept (and block) all the incoming SMS messages and it will forward them to a remote server that is present in clear text in the code of the application. Also the application does not encrypt communications with the remote server and it does not implement obfuscation in the code to make analysis more difficult.<\/li>\n<li>There is no evidence that the intercepted messages are being filtered to target a specific bank or to search for a specific authentication code inside the message. In fact, all the messages are forwarded to the remote server, which makes life more difficult (though possible, using automation) for the Zeus gang because they need to correlate, in real time, the username and password of the user with the mTAN sent in the SMS.<\/li>\n<li>Unlike <a title=\"Zitmo\" href=\"http:\/\/securityblog.s21sec.com\/2010\/09\/zeus-mitmo-man-in-mobile-i.html\" target=\"_blank\" rel=\"noopener noreferrer\">Zitmo,<\/a> this malware does not implement control commands such as SET ADMIN to change the device that is controlling the bots, and it does not have a mechanism to change the URL that is collecting the SMS (in case it is needed).<\/li>\n<\/ul>\n<p>&nbsp;<\/p>\n<p>Although this application was found in one web server that was actively distributing Zeus malware, with the actual evidence and the analyzed application, it is not possible to confirm the Zitmo theory. Moreover, the malware acts as a fake security software (a.k.a. fake alerts), a social engineering technique very common nowadays in malware for personal computers. We expect that more malware for Android will be developed to steal financial information and defeat banking authentication. McAfee products detect this malware in our latest DATs as Android\/SpySMS.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Zeus, also known as ZBot, is one of best-known malware in the industry. The main purpose of this malware is&#8230;<\/p>\n","protected":false},"author":462,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[442],"tags":[37,180,214],"coauthors":[1104],"class_list":["post-9892","post","type-post","status-publish","format-standard","hentry","category-mcafee-labs","tag-android","tag-malware","tag-mobile-security1"],"acf":[],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v25.4 - https:\/\/yoast.com\/wordpress\/plugins\/seo\/ -->\n<title>Dissecting Zeus for Android (or Is It Just SMS Spyware?) | McAfee Blog<\/title>\n<meta name=\"description\" content=\"Zeus, also known as ZBot, is one of best-known malware in the industry. The main purpose of this malware is to steal banking credentials, allowing\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Dissecting Zeus for Android (or Is It Just SMS Spyware?) | McAfee Blog\" \/>\n<meta property=\"og:description\" content=\"Zeus, also known as ZBot, is one of best-known malware in the industry. The main purpose of this malware is to steal banking credentials, allowing\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.mcafee.com\/blogs\/other-blogs\/mcafee-labs\/dissecting-zeus-for-android-or-is-it-just-an-sms-spyware\/\" \/>\n<meta property=\"og:site_name\" content=\"McAfee Blog\" \/>\n<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/McAfee\/\" \/>\n<meta property=\"article:published_time\" content=\"2011-07-12T01:58:21+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2025-05-29T10:40:38+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/www.mcafee.com\/blogs\/wp-content\/uploads\/2011\/07\/fake-vs-real.png\" \/>\n\t<meta property=\"og:image:width\" content=\"306\" \/>\n\t<meta property=\"og:image:height\" content=\"155\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/png\" \/>\n<meta name=\"author\" content=\"Carlos Castillo\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:creator\" content=\"@carlosacastillo\" \/>\n<meta name=\"twitter:site\" content=\"@McAfee\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Carlos Castillo\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"4 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\/\/www.mcafee.com\/blogs\/other-blogs\/mcafee-labs\/dissecting-zeus-for-android-or-is-it-just-an-sms-spyware\/#article\",\"isPartOf\":{\"@id\":\"https:\/\/www.mcafee.com\/blogs\/other-blogs\/mcafee-labs\/dissecting-zeus-for-android-or-is-it-just-an-sms-spyware\/\"},\"author\":{\"name\":\"Carlos Castillo\",\"@id\":\"https:\/\/www.mcafee.com\/blogs\/#\/schema\/person\/894ee4a790607d505a13c24955d2edbe\"},\"headline\":\"Dissecting Zeus for Android (or Is It Just SMS Spyware?)\",\"datePublished\":\"2011-07-12T01:58:21+00:00\",\"dateModified\":\"2025-05-29T10:40:38+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\/\/www.mcafee.com\/blogs\/other-blogs\/mcafee-labs\/dissecting-zeus-for-android-or-is-it-just-an-sms-spyware\/\"},\"wordCount\":880,\"publisher\":{\"@id\":\"https:\/\/www.mcafee.com\/blogs\/#organization\"},\"image\":{\"@id\":\"https:\/\/www.mcafee.com\/blogs\/other-blogs\/mcafee-labs\/dissecting-zeus-for-android-or-is-it-just-an-sms-spyware\/#primaryimage\"},\"thumbnailUrl\":\"https:\/\/www.mcafee.com\/blogs\/wp-content\/uploads\/2011\/07\/fake-vs-real.png\",\"keywords\":[\"android\",\"malware\",\"mobile security\"],\"articleSection\":[\"McAfee Labs\"],\"inLanguage\":\"en-US\"},{\"@type\":\"WebPage\",\"@id\":\"https:\/\/www.mcafee.com\/blogs\/other-blogs\/mcafee-labs\/dissecting-zeus-for-android-or-is-it-just-an-sms-spyware\/\",\"url\":\"https:\/\/www.mcafee.com\/blogs\/other-blogs\/mcafee-labs\/dissecting-zeus-for-android-or-is-it-just-an-sms-spyware\/\",\"name\":\"Dissecting Zeus for Android (or Is It Just SMS Spyware?) | McAfee Blog\",\"isPartOf\":{\"@id\":\"https:\/\/www.mcafee.com\/blogs\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\/\/www.mcafee.com\/blogs\/other-blogs\/mcafee-labs\/dissecting-zeus-for-android-or-is-it-just-an-sms-spyware\/#primaryimage\"},\"image\":{\"@id\":\"https:\/\/www.mcafee.com\/blogs\/other-blogs\/mcafee-labs\/dissecting-zeus-for-android-or-is-it-just-an-sms-spyware\/#primaryimage\"},\"thumbnailUrl\":\"https:\/\/www.mcafee.com\/blogs\/wp-content\/uploads\/2011\/07\/fake-vs-real.png\",\"datePublished\":\"2011-07-12T01:58:21+00:00\",\"dateModified\":\"2025-05-29T10:40:38+00:00\",\"description\":\"Zeus, also known as ZBot, is one of best-known malware in the industry. The main purpose of this malware is to steal banking credentials, allowing\",\"breadcrumb\":{\"@id\":\"https:\/\/www.mcafee.com\/blogs\/other-blogs\/mcafee-labs\/dissecting-zeus-for-android-or-is-it-just-an-sms-spyware\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\/\/www.mcafee.com\/blogs\/other-blogs\/mcafee-labs\/dissecting-zeus-for-android-or-is-it-just-an-sms-spyware\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/www.mcafee.com\/blogs\/other-blogs\/mcafee-labs\/dissecting-zeus-for-android-or-is-it-just-an-sms-spyware\/#primaryimage\",\"url\":\"https:\/\/www.mcafee.com\/blogs\/wp-content\/uploads\/2011\/07\/fake-vs-real.png\",\"contentUrl\":\"https:\/\/www.mcafee.com\/blogs\/wp-content\/uploads\/2011\/07\/fake-vs-real.png\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\/\/www.mcafee.com\/blogs\/other-blogs\/mcafee-labs\/dissecting-zeus-for-android-or-is-it-just-an-sms-spyware\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Blog\",\"item\":\"https:\/\/www.mcafee.com\/blogs\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Other Blogs\",\"item\":\"https:\/\/www.mcafee.com\/blogs\/other-blogs\/\"},{\"@type\":\"ListItem\",\"position\":3,\"name\":\"McAfee Labs\",\"item\":\"https:\/\/www.mcafee.com\/blogs\/other-blogs\/mcafee-labs\/\"},{\"@type\":\"ListItem\",\"position\":4,\"name\":\"Dissecting Zeus for Android (or Is It Just SMS Spyware?)\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\/\/www.mcafee.com\/blogs\/#website\",\"url\":\"https:\/\/www.mcafee.com\/blogs\/\",\"name\":\"McAfee Blog\",\"description\":\"Internet Security News\",\"publisher\":{\"@id\":\"https:\/\/www.mcafee.com\/blogs\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\/\/www.mcafee.com\/blogs\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\/\/www.mcafee.com\/blogs\/#organization\",\"name\":\"McAfee\",\"url\":\"https:\/\/www.mcafee.com\/blogs\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/www.mcafee.com\/blogs\/#\/schema\/logo\/image\/\",\"url\":\"https:\/\/www.mcafee.com\/blogs\/wp-content\/uploads\/2023\/02\/mcafee-logo.png\",\"contentUrl\":\"https:\/\/www.mcafee.com\/blogs\/wp-content\/uploads\/2023\/02\/mcafee-logo.png\",\"width\":1286,\"height\":336,\"caption\":\"McAfee\"},\"image\":{\"@id\":\"https:\/\/www.mcafee.com\/blogs\/#\/schema\/logo\/image\/\"},\"sameAs\":[\"https:\/\/www.facebook.com\/McAfee\/\",\"https:\/\/x.com\/McAfee\",\"https:\/\/www.linkedin.com\/company\/mcafee\/\",\"https:\/\/www.youtube.com\/McAfee\"]},{\"@type\":\"Person\",\"@id\":\"https:\/\/www.mcafee.com\/blogs\/#\/schema\/person\/894ee4a790607d505a13c24955d2edbe\",\"name\":\"Carlos Castillo\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/www.mcafee.com\/blogs\/#\/schema\/person\/image\/729f5b9d2761341175762c5f10652607\",\"url\":\"https:\/\/www.mcafee.com\/blogs\/wp-content\/uploads\/Carlos-Castillo-96x96.jpg\",\"contentUrl\":\"https:\/\/www.mcafee.com\/blogs\/wp-content\/uploads\/Carlos-Castillo-96x96.jpg\",\"caption\":\"Carlos Castillo\"},\"description\":\"Carlos Castillo specializes in the analysis of mobile threats and Android malware. Castillo performs static and dynamic analysis of suspicious applications to support McAfee\u2019s Mobile Security for Android product. He is the author of the McAfee-published white paper, \\\"Android Malware Past, Present, and Future,\u201d and wrote the \u201cHacking Android\\\" section of the book, \\\"Hacking Exposed 7: Network Security Secrets &amp; Solutions.\u201d As a recognized mobile malware researcher, Castillo has presented at several security industry events, including 8.8 Computer Security Conference and Segurinfo, a leading information security conference in South America. Prior to his position at McAfee, Castillo performed security compliance audits for the Superintendencia Financiera of Colombia, and worked at security startup Easy Solutions Inc., where he conducted penetration tests on web applications, helped shut down phishing and malicious websites, supported security and network appliances, performed functional software testing, and assisted in research and development related to anti-electronic fraud. Castillo joined the world of malware research when he won ESET Latin America\u2019s Best Antivirus Research contest with a paper titled, \u201cSexy View: The Beginning of Mobile Botnets.\u201d Castillo holds a degree in systems engineering from the Universidad Javeriana in Bogot\u00e1, Colombia.\",\"sameAs\":[\"https:\/\/www.linkedin.com\/in\/carlosacastillo\/\",\"https:\/\/x.com\/carlosacastillo\"],\"url\":\"https:\/\/www.mcafee.com\/blogs\/author\/carlos-castillo\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Dissecting Zeus for Android (or Is It Just SMS Spyware?) | McAfee Blog","description":"Zeus, also known as ZBot, is one of best-known malware in the industry. The main purpose of this malware is to steal banking credentials, allowing","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"og_locale":"en_US","og_type":"article","og_title":"Dissecting Zeus for Android (or Is It Just SMS Spyware?) | McAfee Blog","og_description":"Zeus, also known as ZBot, is one of best-known malware in the industry. The main purpose of this malware is to steal banking credentials, allowing","og_url":"https:\/\/www.mcafee.com\/blogs\/other-blogs\/mcafee-labs\/dissecting-zeus-for-android-or-is-it-just-an-sms-spyware\/","og_site_name":"McAfee Blog","article_publisher":"https:\/\/www.facebook.com\/McAfee\/","article_published_time":"2011-07-12T01:58:21+00:00","article_modified_time":"2025-05-29T10:40:38+00:00","og_image":[{"width":306,"height":155,"url":"https:\/\/www.mcafee.com\/blogs\/wp-content\/uploads\/2011\/07\/fake-vs-real.png","type":"image\/png"}],"author":"Carlos Castillo","twitter_card":"summary_large_image","twitter_creator":"@carlosacastillo","twitter_site":"@McAfee","twitter_misc":{"Written by":"Carlos Castillo","Est. reading time":"4 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/www.mcafee.com\/blogs\/other-blogs\/mcafee-labs\/dissecting-zeus-for-android-or-is-it-just-an-sms-spyware\/#article","isPartOf":{"@id":"https:\/\/www.mcafee.com\/blogs\/other-blogs\/mcafee-labs\/dissecting-zeus-for-android-or-is-it-just-an-sms-spyware\/"},"author":{"name":"Carlos Castillo","@id":"https:\/\/www.mcafee.com\/blogs\/#\/schema\/person\/894ee4a790607d505a13c24955d2edbe"},"headline":"Dissecting Zeus for Android (or Is It Just SMS Spyware?)","datePublished":"2011-07-12T01:58:21+00:00","dateModified":"2025-05-29T10:40:38+00:00","mainEntityOfPage":{"@id":"https:\/\/www.mcafee.com\/blogs\/other-blogs\/mcafee-labs\/dissecting-zeus-for-android-or-is-it-just-an-sms-spyware\/"},"wordCount":880,"publisher":{"@id":"https:\/\/www.mcafee.com\/blogs\/#organization"},"image":{"@id":"https:\/\/www.mcafee.com\/blogs\/other-blogs\/mcafee-labs\/dissecting-zeus-for-android-or-is-it-just-an-sms-spyware\/#primaryimage"},"thumbnailUrl":"https:\/\/www.mcafee.com\/blogs\/wp-content\/uploads\/2011\/07\/fake-vs-real.png","keywords":["android","malware","mobile security"],"articleSection":["McAfee Labs"],"inLanguage":"en-US"},{"@type":"WebPage","@id":"https:\/\/www.mcafee.com\/blogs\/other-blogs\/mcafee-labs\/dissecting-zeus-for-android-or-is-it-just-an-sms-spyware\/","url":"https:\/\/www.mcafee.com\/blogs\/other-blogs\/mcafee-labs\/dissecting-zeus-for-android-or-is-it-just-an-sms-spyware\/","name":"Dissecting Zeus for Android (or Is It Just SMS Spyware?) | McAfee Blog","isPartOf":{"@id":"https:\/\/www.mcafee.com\/blogs\/#website"},"primaryImageOfPage":{"@id":"https:\/\/www.mcafee.com\/blogs\/other-blogs\/mcafee-labs\/dissecting-zeus-for-android-or-is-it-just-an-sms-spyware\/#primaryimage"},"image":{"@id":"https:\/\/www.mcafee.com\/blogs\/other-blogs\/mcafee-labs\/dissecting-zeus-for-android-or-is-it-just-an-sms-spyware\/#primaryimage"},"thumbnailUrl":"https:\/\/www.mcafee.com\/blogs\/wp-content\/uploads\/2011\/07\/fake-vs-real.png","datePublished":"2011-07-12T01:58:21+00:00","dateModified":"2025-05-29T10:40:38+00:00","description":"Zeus, also known as ZBot, is one of best-known malware in the industry. The main purpose of this malware is to steal banking credentials, allowing","breadcrumb":{"@id":"https:\/\/www.mcafee.com\/blogs\/other-blogs\/mcafee-labs\/dissecting-zeus-for-android-or-is-it-just-an-sms-spyware\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.mcafee.com\/blogs\/other-blogs\/mcafee-labs\/dissecting-zeus-for-android-or-is-it-just-an-sms-spyware\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.mcafee.com\/blogs\/other-blogs\/mcafee-labs\/dissecting-zeus-for-android-or-is-it-just-an-sms-spyware\/#primaryimage","url":"https:\/\/www.mcafee.com\/blogs\/wp-content\/uploads\/2011\/07\/fake-vs-real.png","contentUrl":"https:\/\/www.mcafee.com\/blogs\/wp-content\/uploads\/2011\/07\/fake-vs-real.png"},{"@type":"BreadcrumbList","@id":"https:\/\/www.mcafee.com\/blogs\/other-blogs\/mcafee-labs\/dissecting-zeus-for-android-or-is-it-just-an-sms-spyware\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Blog","item":"https:\/\/www.mcafee.com\/blogs\/"},{"@type":"ListItem","position":2,"name":"Other Blogs","item":"https:\/\/www.mcafee.com\/blogs\/other-blogs\/"},{"@type":"ListItem","position":3,"name":"McAfee Labs","item":"https:\/\/www.mcafee.com\/blogs\/other-blogs\/mcafee-labs\/"},{"@type":"ListItem","position":4,"name":"Dissecting Zeus for Android (or Is It Just SMS Spyware?)"}]},{"@type":"WebSite","@id":"https:\/\/www.mcafee.com\/blogs\/#website","url":"https:\/\/www.mcafee.com\/blogs\/","name":"McAfee Blog","description":"Internet Security News","publisher":{"@id":"https:\/\/www.mcafee.com\/blogs\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.mcafee.com\/blogs\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/www.mcafee.com\/blogs\/#organization","name":"McAfee","url":"https:\/\/www.mcafee.com\/blogs\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.mcafee.com\/blogs\/#\/schema\/logo\/image\/","url":"https:\/\/www.mcafee.com\/blogs\/wp-content\/uploads\/2023\/02\/mcafee-logo.png","contentUrl":"https:\/\/www.mcafee.com\/blogs\/wp-content\/uploads\/2023\/02\/mcafee-logo.png","width":1286,"height":336,"caption":"McAfee"},"image":{"@id":"https:\/\/www.mcafee.com\/blogs\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/www.facebook.com\/McAfee\/","https:\/\/x.com\/McAfee","https:\/\/www.linkedin.com\/company\/mcafee\/","https:\/\/www.youtube.com\/McAfee"]},{"@type":"Person","@id":"https:\/\/www.mcafee.com\/blogs\/#\/schema\/person\/894ee4a790607d505a13c24955d2edbe","name":"Carlos Castillo","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.mcafee.com\/blogs\/#\/schema\/person\/image\/729f5b9d2761341175762c5f10652607","url":"https:\/\/www.mcafee.com\/blogs\/wp-content\/uploads\/Carlos-Castillo-96x96.jpg","contentUrl":"https:\/\/www.mcafee.com\/blogs\/wp-content\/uploads\/Carlos-Castillo-96x96.jpg","caption":"Carlos Castillo"},"description":"Carlos Castillo specializes in the analysis of mobile threats and Android malware. Castillo performs static and dynamic analysis of suspicious applications to support McAfee\u2019s Mobile Security for Android product. He is the author of the McAfee-published white paper, \"Android Malware Past, Present, and Future,\u201d and wrote the \u201cHacking Android\" section of the book, \"Hacking Exposed 7: Network Security Secrets &amp; Solutions.\u201d As a recognized mobile malware researcher, Castillo has presented at several security industry events, including 8.8 Computer Security Conference and Segurinfo, a leading information security conference in South America. Prior to his position at McAfee, Castillo performed security compliance audits for the Superintendencia Financiera of Colombia, and worked at security startup Easy Solutions Inc., where he conducted penetration tests on web applications, helped shut down phishing and malicious websites, supported security and network appliances, performed functional software testing, and assisted in research and development related to anti-electronic fraud. Castillo joined the world of malware research when he won ESET Latin America\u2019s Best Antivirus Research contest with a paper titled, \u201cSexy View: The Beginning of Mobile Botnets.\u201d Castillo holds a degree in systems engineering from the Universidad Javeriana in Bogot\u00e1, Colombia.","sameAs":["https:\/\/www.linkedin.com\/in\/carlosacastillo\/","https:\/\/x.com\/carlosacastillo"],"url":"https:\/\/www.mcafee.com\/blogs\/author\/carlos-castillo\/"}]}},"_links":{"self":[{"href":"https:\/\/www.mcafee.com\/blogs\/wp-json\/wp\/v2\/posts\/9892","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.mcafee.com\/blogs\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.mcafee.com\/blogs\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.mcafee.com\/blogs\/wp-json\/wp\/v2\/users\/462"}],"replies":[{"embeddable":true,"href":"https:\/\/www.mcafee.com\/blogs\/wp-json\/wp\/v2\/comments?post=9892"}],"version-history":[{"count":3,"href":"https:\/\/www.mcafee.com\/blogs\/wp-json\/wp\/v2\/posts\/9892\/revisions"}],"predecessor-version":[{"id":214721,"href":"https:\/\/www.mcafee.com\/blogs\/wp-json\/wp\/v2\/posts\/9892\/revisions\/214721"}],"wp:attachment":[{"href":"https:\/\/www.mcafee.com\/blogs\/wp-json\/wp\/v2\/media?parent=9892"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.mcafee.com\/blogs\/wp-json\/wp\/v2\/categories?post=9892"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.mcafee.com\/blogs\/wp-json\/wp\/v2\/tags?post=9892"},{"taxonomy":"author","embeddable":true,"href":"https:\/\/www.mcafee.com\/blogs\/wp-json\/wp\/v2\/coauthors?post=9892"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}