BadNews

Malware

⚠️ Overview

BadNews is a family of Android Trojan malware first identified in April 2013 by Lookout Mobile Security. The malware was distributed through third-party app stores, disguised as legitimate applications such as news apps, games, and utilities. BadNews functions primarily as a premium SMS sender, a category of malware that generates revenue by silently subscribing victims to costly SMS services without their consent. The threat actor behind BadNews is believed to be a Russian-based group known as the "Russian fraudsters" or "SMS Trojan operators," though specific attribution remains unconfirmed.

🔧 Technical Capabilities

BadNews operates by intercepting incoming SMS messages, particularly those containing confirmation codes for premium services, and deleting them to hide evidence of unauthorized subscriptions. It establishes command-and-control (C2) communication over HTTP to a remote server, where it receives instructions for sending premium-rate SMS messages to predefined numbers. The malware does not self-propagate; instead, it relies on social engineering and repackaging of legitimate apps to distribute through third-party stores. Persistence is achieved through Android’s BOOT_COMPLETED broadcast receiver, ensuring the malware restarts after device reboot. Evasion techniques include obfuscation of the malicious payload using encryption and delaying activation to avoid detection during initial installation. No known privilege escalation or root exploits were used; the malware operates within standard application permissions.

📜 History & Notable Incidents

First discovered in April 2013, Lookout reported that BadNews applications had been downloaded between 2 million and 9 million times from third-party app stores, primarily in Russia, Ukraine, and other Eastern European countries. A notable campaign involved the "NewsAndroid" app, which appeared legitimate but contained the BadNews payload. No specific CVEs were assigned, as the malware exploited no system vulnerabilities but relied on user-installed apps. Law enforcement actions are not documented publicly; however, the malware’s C2 infrastructure was dismantled by security researchers in coordination with hosting providers.

🔍 Detection Indicators

File hashes for BadNews variants are scarce in public repositories, but Lookout (now part of Zimperium) provides YARA rules. Behavioral signatures include excessive SMS message interception and deletion, especially of incoming messages from short codes or premium numbers. Network IOCs include HTTP requests to domains such as "news-android.com" and "badnews-android.com" (since taken down). The malware commonly requests the android.permission.RECEIVE_SMS, android.permission.READ_SMS, and android.permission.SEND_SMS permissions. No unique mutex or registry keys apply, as this is Android malware. The malware checks for the presence of com.android.settings package to avoid detection in analysis environments.

☠️ Risk & Impact

The primary damage from BadNews is financial, as victims incur charges from premium SMS services—often hundreds of dollars per infected device. No data exfiltration has been reported beyond phone numbers and SMS content. The malware predominantly affected users in Eastern Europe and Russia, but some infections were observed in the United States and Western Europe through international premium-rate numbers. Industries most impacted include mobile users of third-party app stores, particularly those downloading free news and entertainment apps.

🛡️ Mitigation

Mitigation involves avoiding installation of apps from third-party stores and verifying permissions—especially SMS-related permissions on seemingly unrelated apps. Mobile security solutions such as Lookout, Kaspersky, and Malwarebytes detect BadNews, and Android’s Play Protect (when active) blocks known variants. No specific patch is needed, as the malware exploits user behavior, not OS vulnerabilities. Regular scanning and disabling SMS interception capabilities through system tools are recommended.

A Large Share of Web Traffic Is Automated — Not All of It Is Benign

— Industry Security Reports

Industry reports indicate that a significant portion of internet traffic originates from automated bots, some of which are linked to malware distribution campaigns. See what's reaching your server.

📊 Get My Threat Report

Sign up in seconds  ·  No card required

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.