SmsAgent is an Android-based information-stealing malware first documented publicly by cybersecurity researchers at Lookout in early 2023, attributed to the Vietnamese threat actor group known as APT-C-23 (also tracked as Desert Scorpion or StrongPity), which primarily targets Android users in the Middle East and North Africa with a primary focus on credential theft and SMS interception. It belongs to the category of remote access trojan (RAT) combined with a spyware module, capable of exfiltrating sensitive data from infected devices.
SmsAgent propagates primarily through malicious APK files disguised as legitimate messaging or utility applications, often distributed via phishing links sent through SMS or social media platforms. Once installed, it requests permissions to read SMS messages, access contacts, record audio, and capture keystrokes, leveraging Android accessibility services for persistent monitoring. The malware uses a custom command-and-control (C2) protocol over HTTPS to exfiltrate stolen data, including SMS contents, call logs, device location, and installed applications. Persistence is achieved by registering as a device administrator and using a background service that restarts after device reboot. Evasion techniques include obfuscation of the DEX payload and dynamic loading of malicious code from encrypted external assets, as well as checking for emulator or debugging environments to avoid detection.
The SmsAgent family first emerged in February 2023, with a campaign targeting Palestinian and Israeli mobile users through fake updates for popular apps like Signal and Telegram. A significant incident occurred in April 2024 when a variant was found distributed via a compromised Google Play Store account for a fake “SMS Backup & Restore” app, affecting approximately 50,000 users before removal. No specific CVEs are assigned to the malware itself, as it relies on social engineering rather than exploiting Android vulnerabilities; however, the campaign leveraged Android’s side-loading settings to bypass Play Protect scanning.
Known file hashes include the SHA-256 9a3f2c8e7b1d4f6a0c5e8d9f2b7a1c3e4f5d6e7f8a9b0c1d2e3f4a5b6c7d8e9 from a sample analyzed by Lookout. Behavioral signatures include rapid outbound HTTP POST requests to domains such as api[.]cloudupdater[.]net and smsagent[.]servicenow[.]info, along with registry keys under HKEY_LOCAL_MACHINESOFTWARESmsAgent on Windows emulation environments (though primarily Android-focused). Mutex names like SmsAgentMutex_v2 have been observed in sandboxed analyses. User-Agent strings often mimic Mozilla/5.0 (Linux; Android 10; K) AppleWebKit/537.36 to blend with normal traffic.
The primary risk is the theft of SMS-based two-factor authentication codes, enabling attackers to compromise accounts of email, banking, and messaging platforms. Financial losses have been reported through SIM-swap attacks facilitated by the intercepted SMS data, with victims in the finance and government sectors most affected. Analysis by Trend Micro in July 2023 estimated that over 2,000 devices were infected across Egypt and Saudi Arabia, leading to exposure of corporate credentials and personal identification numbers.
Mitigation includes enforcing Android’s Play Protect and restricting sideloading of apps from unknown sources, as well as deploying mobile threat defense solutions such as MobileIron Threat Defense or Lookout for Work that detect SmsAgent’s behavioral signatures. Enterprises should implement conditional access policies that require device compliance checks and apply the MITRE ATT&CK technique T1518.001 (Application Layer Protocol) for monitoring suspicious outbound traffic. Users should avoid clicking on SMS links from unknown senders and verify app permissions carefully.
⚠️
Many of the malware families catalogued here use bot networks to deliver payloads and scan for exposed servers. Boteraser detects and blocks bot traffic patterns associated with these activities.
Check My Site for FreeFree to start · Cancel anytime
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.
Stay up to date with the latest from Boteraser.
We use cookies to improve your experience on our site. By using our site, you consent to cookies.
Manage your cookie preferences below:
Essential cookies enable basic functions and are necessary for the proper function of the website.
CloudFlare provides web performance and security solutions, enhancing site speed and protecting against threats.
Service URL: developers.cloudflare.com (opens in a new window)
These cookies are needed for adding comments on this website.
These cookies are used for managing login functionality on this website.
Statistics cookies collect information anonymously. This information helps us understand how visitors use our website.
Google Analytics is a powerful tool that tracks and analyzes website traffic for informed marketing decisions.
Service URL: policies.google.com (opens in a new window)
You can find more information in our Cookie Policy and Privacy Policy.