| Type | Behavior | |------|-----------| | | Scans device, shows fake "critical firmware errors", demands payment to "fix". | | Clicker Trojan | Simulates ad clicks in background using accessibility services. | | Data stealer | Uploads IMEI, phone number, contacts, SMS to remote server. | | Rooting tool + backdoor | Uses old exploits (Dirty Cow, Towelroot) to root device, then installs persistent malware. | | FRP bypass tool (gray area) | Attempts to bypass Google account verification using exploits; often bundled with adware. |