• apps
  • games
  • desktop

GamCare Calls For Crypto Trading Self-Exclusion: Will GamStop Take Actions?

August 16, 2023

Gamestop Insiders Continue Buying GME Stock

August 16, 2023

Ryan Cohen scoops up GameStop stock worth $10 million, shares rise

August 16, 2023

Jack Dorsey’s Damus may be thwarted by Apple’s strict payment rules

August 16, 2023
Facebook Twitter Instagram
  • Terms of Use
  • Privacy Policy
  • Cookie Privacy Policy
  • DMCA
  • California Consumer Privacy Act (CCPA)
  • contact-us
Facebook Twitter Instagram
appsapps
Demo
  • apps
  • games
  • desktop
appsapps
Home » ‘Dangerous’ spyware apps discovered on Google Play Store
apps

‘Dangerous’ spyware apps discovered on Google Play Store

apkappsBy apkappsJuly 29, 2023Updated:July 31, 2023No Comments3 Mins Read
Facebook Twitter LinkedIn Telegram Pinterest Tumblr Reddit Email
‘Dangerous’ spyware apps discovered on Google Play Store
Share
Facebook Twitter LinkedIn Pinterest Email


Cybersecurity researchers have discovered three apps on Google Play Store that were reportedly used by state-sponsored hackers to collect intelligence from targeted devices. This information includes location data and contact lists of victims. According to a report by Singapore-based cybersecurity company Cyfirma, the operation was attributed to the hacking group “DoNot”.
The hacking group reportedly targeted high-profile organisations in Southeast Asia since 2018, reports Bleeping Computer.
The apps used in DoNot‘s latest campaign collect basic information. This data can help the threat group prepare the ground for more dangerous malware attacks. The latest campaign also reportedly represents the first stage of the group’s attacks.
Google Play Store apps spreading spyware
As per Cyfirma, the suspected apps that are reportedly spreading spyware to collect data are available on Google Play Store. Both these apps, nSure Chat and iKHfaa VPN have been uploaded by the developer named ‘SecurITY Industry.’
Meanwhile, the publisher also has a third app on Play Store which didn’t appear malicious for Cyfirma. We at TOI-GadgetsNow have searched the Google Play Store for these apps. The iKHfaa VPN seemed to have been removed while the nSure Chat app is still available on the platform and Google is still allowing users to download it.
The download count on the apps developed by the ‘SecurITY Industry’ is comparatively low. This suggests that these apps are used selectively against specific targets.
How these apps are stealing data
The report claims that these apps request users for risky permissions during installation. These permissions include access to the user’s contact list and precise location data. The apps then collect this data and send them to the attacker.
However, to access the target’s current location, the GPS on the victim’s device needs to be active. In other cases, the app fetches the last known location of the device. The collected data is stored locally using Android‘s ROOM library. This data is later sent to the attacker’s C2 server via an HTTP request.

Cyfirma analysts have also discovered that the code base of the hackers’ VPN app was copied from the legitimate Liberty VPN service.
How Cyfirma linked the operation to DoNot
The cybersecurity firm attributed the campaign to the DoNot threat group based on the specific use of encrypted strings. The techniques were associated with the alleged hacking group. The company also discovered that certain file names generated by the malicious apps were also linked to past DoNot campaigns.
Cyfirma researchers hint that the attackers have abandoned the tactic of sending phishing emails carrying malicious attachments. Instead, the group is now employing spear messaging attack tactics via WhatsApp and Telegram messaging platforms. Links send via direct messages on these apps send victims to the Google Play Store. Android’s app store is a trusted platform which also helps the attack to be legitimate. This helps the attackers easily trick victims into downloading suggested apps.





Source link

Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
apkapps
  • Website

Related Posts

Jack Dorsey’s Damus may be thwarted by Apple’s strict payment rules

August 16, 2023

Traffic apps are routing drivers to N.J. after I-95 collapse in Philly

August 16, 2023

Realme 11 Pro+ 5G with 200 MP camera goes on first sale in India today on Flipkart: Price, offers, specs

August 14, 2023

Reddit blackout explained | CTV News

August 14, 2023

Hindi translation at the Bushplane? There’s an app for that

August 14, 2023

3D app uncovers lost Mughrabi quarter of Jerusalem’s Old City – Global

August 14, 2023

Leave A Reply Cancel Reply

games

GamCare Calls For Crypto Trading Self-Exclusion: Will GamStop Take Actions?

By apkappsAugust 16, 2023

importance of promoting responsible trading practices.The requirement for traders to exclude themselves voluntarily.The occurrence…

games

Gamestop Insiders Continue Buying GME Stock

By apkappsAugust 16, 2023

In recent days, the shares of Gamestop (NYSE:GME) have experienced a surge following news that…

games

Ryan Cohen scoops up GameStop stock worth $10 million, shares rise

By apkappsAugust 16, 2023

The story continues below these videos from Saltwire. According to a securities filing, Ryan…

apps

Jack Dorsey’s Damus may be thwarted by Apple’s strict payment rules

By apkappsAugust 16, 2023

On November 12, 2018, Jack Dorsey, the CEO of Twitter, spoke to students at the…

Facebook Twitter Instagram Pinterest
  • Terms of Use
  • Privacy Policy
  • Cookie Privacy Policy
  • DMCA
  • California Consumer Privacy Act (CCPA)
  • contact-us
© 2023 ThemeSphere. Designed by ThemeSphere.

Type above and press Enter to search. Press Esc to cancel.