iOS/Android Trojan Discovered in "Find and Call" app
A trojan for iOS/Android was discovered in the iTunes App and Google Play stores. The trojan was part of an app called "Find and Call" which, when installed, requested access to the address book data. If access was granted, the app uploaded contact data to a remote server where the server would then proceed to send an SMS message to each contact number. These SMS messages arrived with links to download the application. The SMS messages were spoofed to appear to have come from the person who provided their address book data. The app has since been removed from both stores.
More details here: https://www.securelist.com/en/blog/208193641/Find_and_Call_Leak_and_Spam
