Navigation and service

AndroidBauts

Name of Malware: Bauts (AndroidBauts)

warning triangle red

Type of Malware: Adware, click fraud, dropper, potentially unwanted application (PUA/PUP), SDK/programming tool

Affected Operating System: Android (from Version 4.1.1)

Affected Device Types: Mobile phones, smartphones, tablets

Impact:high

What is AndroidBauts?

AndroidBauts is a piece of adware and a potentially unwanted application (PUA) for Android devices. It is integrated into other applications as part of the "snowfox" software development kit ("SFoxSDK") to display advertisements. However, the adware also has a number of other functions, including some designed to track users without authorisation. In particular, these functions allow device-specific information such as IMEI, IMSI and GPS position to be exfiltrated to external servers. However, what makes this adware particularly dangerous is its ability to download other applications from these servers and to install them without any confirmation or interaction from the user.

How did I get infected with AndroidBauts?

AndroidBauts relies on the user actively installing an infected application, which is normally hidden within another software package that appears completely harmless.

What do I have to do now?

The device that is at risk can be cleaned by removing the app in question.

Further information can be found under Removing infections on smartphones and tablets.