October 30, 2018 By David Bisson 2 min read

A recent investigation into an active phishing campaign uncovered a malware family that enables attackers to turn infected Android devices into network proxies without users’ knowledge.

According to the McAfee Mobile Research team, the campaign uses text messages to trick users into downloading the malware, known as TimpDoor, which is disguised as a fake voice messaging app. Once the user closes the app after installation completes, the app’s icon disappears from the home screen and secretly starts running a background service that allows the malware to gather device information, including the operating system (OS) version and connection type.

At that point, the malware initiates a secure shell (SSH) connection to the control server to retrieve an assigned remote port. The port enables the malware to use the device as a local Socket Secure (SOCKS) proxy server for port forwarding, which attackers can then employ to access corporate networks, send spam and phishing emails, perform ad-click fraud, and launch distributed denial-of-service (DDoS) attacks.

According to McAfee’s findings, TimpDoor has been active since March 2018 and has thus far infected at least 5,000 devices.

How Threat Actors Turn Infected Android Devices Into Network Proxies

TimpDoor isn’t the first malware that’s turned infected Android devices into network proxies. In April 2017, researchers at Trend Micro detected MilkyDoor malware — a successor to DressCode malware discovered by Check Point a year earlier — which masqueraded as apps available for download on the Google Play Store.

MilkyDoor also uses remote port forwarding via SSH to protect the connection and bypass network security restrictions. But while TimpDoor was designed to keep the SSH tunnel open and the proxy server running, MilkyDoor added backdoor functionality on top of its main role as an adware integrator.

How to Defend Against TimpDoor Malware

Security professionals can defend against TimpDoor malware by following mobile threat prevention best practices, such as using an app to scan approved devices and configurations for anomalous connections. Such a strategy enables security professionals to monitor and analyze how apps behave across user devices, flag suspicious events and take action accordingly.

Sources: McAfee, Trend Micro, Check Point

More from

FYSA — VMware Critical Vulnerabilities Patched

< 1 min read - SummaryBroadcom has released a security bulletin, VMSA-2025-0004, addressing and remediating three vulnerabilities that, if exploited, could lead to system compromise. Products affected include vCenter Server, vRealize Operations Manager, and vCloud Director.Threat TopographyThreat Type: Critical VulnerabilitiesIndustry: VirtualizationGeolocation: GlobalOverviewX-Force Incident Command is monitoring activity surrounding Broadcom’s Security Bulletin (VMSA-2025-0004) for three potentially critical vulnerabilities in VMware products. These vulnerabilities, identified as CVE-2025-22224, CVE-2025-22225, and CVE-2025-22226, have reportedly been exploited in attacks. X-Force has not been able to validate those claims. The vulnerabilities…

SoaPy: Stealthy enumeration of Active Directory environments through ADWS

10 min read - Introduction Over time, both targeted and large-scale enumeration of Active Directory (AD) environments have become increasingly detected due to modern defensive solutions. During our internship at X-Force Red this past summer, we noticed FalconForce’s SOAPHound was becoming popular for enumerating Active Directory environments. This tool brought a new perspective to Active Directory enumeration by performing collection via Active Directory Web Services (ADWS) instead of directly through Lightweight Directory Access Protocol (LDAP) as other AD enumeration tools had in the past.…

Smoltalk: RCE in open source agents

26 min read - Big shoutout to Hugging Face and the smolagents team for their cooperation and quick turnaround for a fix! Introduction Recently, I have been working on a side project to automate some pentest reconnaissance with AI agents. Just after I started this project, Hugging Face announced the release of smolagents, a lightweight framework for building AI agents that implements the methodology described in the ReAct paper, emphasizing reasoning through iterative decision-making. Interestingly, smolagents enables agents to reason and act by generating…

Topic updates

Get email updates and stay ahead of the latest threats to the security landscape, thought leadership and research.
Subscribe today