First Trojan for Android Phones Goes Wild [UPDATE]
Google Android phones must be popular - they've just been targeted with their first Trojan. An SMS Trojan called Trojan-SMS.AndroidOS.FakePlayer.a has already infected a number of mobile devices, according to security firm Kaspersky Lab.
Context & Ripple Effects
Three years after malware sellers went chasing the iPhone — SunbeltBLOG covered a hot phone being sold through malware in June 2007 — Android has crossed the same threshold. Kaspersky Lab confirms that Trojan-SMS.AndroidOS.FakePlayer.a has infected multiple devices, making it the platform's first documented Trojan, and ReadWriteWeb frames the timing itself as a popularity signal.
What distinguishes this malware family from the PC-era threats readers know is its payout mechanism: an SMS Trojan bills victims straight through their phone accounts, so every infected handset generates revenue immediately rather than requiring stolen data to be resold downstream.
First-order effects
- Users on infected handsets are charged for text messages they never sent, with the cost landing on their phone bills until the malware is found and removed.
- Kaspersky Lab gets both a detection job and a franchise moment: by naming and confirming the threat, it stakes its claim as the authority on Android protection at exactly the moment the platform needs one.
Second-order effects
- Mobile antivirus vendors gain their first concrete Android sales pitch, turning handset security software from an optional extra into something consumers may actually buy.
- Carriers absorb the fallout on the billing side — unauthorized SMS charges route through operator accounts, creating dispute, refund, and fraud-screening workload that did not exist when phones were closed devices.
Third-order effects
- If popularity keeps drawing attackers, as the 2007 iPhone episode suggested it would, app-distribution policy becomes a security differentiator in the Android-versus-Apple rivalry rather than just a developer-preference question.
- Repeated SMS-fraud incidents push platform holders and carriers toward building protections into the OS and network themselves instead of leaving detection entirely to third-party antivirus.
The trend: Smartphone platforms cross a criminal-monetization threshold once they reach mass adoption — pulling SMS fraud onto phones and dragging the security industry with them, a path the iPhone already signaled in 2007.