Yeah, I read articles calling it sophisticated. This is a super simple and straight forward worm. Disguise yourself as a known app and ask for more permission than you should. IDN exploits [0] and attachment faking [1] are more sophisticated if anything.
[0] https://www.wordfence.com/blog/2017/04/chrome-firefox-unicod...
[1] http://fortune.com/2017/01/18/google-gmail-scam-phishing/