Blue Coat Systems recently released a paper about the Inception APT (also dubbed Cloud Atlas, it may be connected to the Red October APT). One component of this APT is an Android trojan, masquerading as a Whatsapp update package. It is able to record audio calls, as well as gather, encrypt and exfiltrate user information.
The 4 strings partially written in Hindi that have been speculated on are those:
For researchers wanting to have a peak inside the APK, we are providing JEB decompiled Java code for one such sample.
Download is here: cloudatlas-android-malware-decompiled.zip