{"id":2293,"date":"2023-06-20T16:41:50","date_gmt":"2023-06-20T11:11:50","guid":{"rendered":"https:\/\/bscrackers.com\/?p=2293"},"modified":"2023-06-20T16:41:50","modified_gmt":"2023-06-20T11:11:50","slug":"dangerous-spyware-apps-discovered-on-google-play-store","status":"publish","type":"post","link":"https:\/\/bscrackers.com\/?p=2293","title":{"rendered":"\u2018Dangerous\u2019 spyware apps discovered on Google Play Store"},"content":{"rendered":"<p> [ad_1]<br \/>\n<br \/><img decoding=\"async\" src=\"https:\/\/static.toiimg.com\/photo\/msid-101135208,imgsize-10484.cms\" \/><\/p>\n<div>Cybersecurity researchers have discovered three apps on <!-- -->Google Play Store<!-- --> that were reportedly used by state-sponsored hackers to collect intelligence from targeted devices. This information includes location data and contact lists of victims. According to a report by Singapore-based cybersecurity company Cyfirma, the operation was attributed to the hacking group &#8220;DoNot\u201d.<br \/>The hacking group reportedly targeted high-profile organisations in Southeast Asia since 2018, reports Bleeping Computer. <br \/>The apps used in <!-- -->DoNot<!-- -->&#8216;s latest campaign collect basic information. This data can help the threat group prepare the ground for more dangerous malware attacks. The latest campaign also reportedly represents the first stage of the group&#8217;s attacks. <br \/><span class=\"strong\">Google Play Store apps spreading spyware<\/span><br \/>As per Cyfirma, the suspected apps that are reportedly spreading spyware to collect data are available on <!-- -->Google<!-- --> Play Store. Both these apps, <!-- -->nSure Chat<!-- --> and iKHfaa VPN have been uploaded by the developer named &#8216;<!-- -->SecurITY Industry<!-- -->.&#8217;<br \/>Meanwhile, the publisher also has a third app on Play Store which didn\u2019t appear malicious for Cyfirma. We at TOI-GadgetsNow have searched the Google Play Store for these apps. The iKHfaa VPN seemed to have been removed while the nSure Chat app is still available on the platform and Google is still allowing users to download it.<br \/>The download count on the apps developed by the \u2018SecurITY Industry\u2019 is comparatively low. This suggests that these apps are used selectively against specific targets.<br \/><span class=\"strong\">How these apps are stealing data<\/span><br \/>The report claims that these apps request users for risky permissions during installation. These permissions include access to the user&#8217;s contact list and precise location data. The apps then collect this data and send them to the attacker. <br \/>However, to access the target&#8217;s current location, the GPS on the victim\u2019s device needs to be active. In other cases, the app fetches the last known location of the device. The collected data is stored locally using <!-- -->Android<!-- -->&#8216;s ROOM library. This data is later sent to the attacker&#8217;s C2 server via an HTTP request.<\/p>\n<p>Cyfirma analysts have also discovered that the code base of the hackers&#8217; VPN app was copied from the legitimate <!-- -->Liberty VPN<!-- --> service. <br \/><span class=\"strong\">How Cyfirma linked the operation to DoNot<\/span><br \/>The cybersecurity firm attributed the campaign to the DoNot threat group based on the specific use of encrypted strings. The techniques were associated with the alleged hacking group. The company also discovered that certain file names generated by the malicious apps were also linked to past DoNot campaigns.<br \/>Cyfirma researchers hint that the attackers have abandoned the tactic of sending phishing emails carrying malicious attachments. Instead, the group is now employing spear messaging attack tactics via WhatsApp and <!-- -->Telegram<!-- --> messaging platforms. Links send via direct messages on these apps send victims to the Google Play Store. Android\u2019s app store is a trusted platform which also helps the attack to be legitimate. This helps the attackers easily trick victims into downloading suggested apps.<\/p>\n<\/div>\n<p><script>!(function(f, b, e, v, n, t, s) {\n    function loadFBEvents(isFBCampaignActive) \n      if (!isFBCampaignActive) \n        return;<\/p>\n<p>      (function(f, b, e, v, n, t, s) \n        if (f.fbq) return;\n        n = f.fbq = function() \n          n.callMethod ? n.callMethod(...arguments) : n.queue.push(arguments);\n        ;\n        if (!f._fbq) f._fbq = n;\n        n.push = n;\n        n.loaded = !0;\n        n.version = '2.0';\n        n.queue = [];\n        t = b.createElement(e);\n        t.async = !0;\n        t.defer = !0;\n        t.src = v;\n        s = b.getElementsByTagName(e)[0];\n        s.parentNode.insertBefore(t, s);\n      )(f, b, e, 'https:\/\/connect.facebook.net\/en_US\/fbevents.js', n, t, s);\n      fbq('init', '593671331875494');\n      fbq('track', 'PageView');\n    ;<\/p>\n<p>    function loadGtagEvents(isGoogleCampaignActive) \n      if (!isGoogleCampaignActive) \n        return;<\/p>\n<p>      var id = document.getElementById('toi-plus-google-campaign');\n      if (id) \n        return;<\/p>\n<p>      (function(f, b, e, v, n, t, s) \n        t = b.createElement(e);\n        t.async = !0;\n        t.defer = !0;\n        t.src = v;\n        t.id = 'toi-plus-google-campaign';\n        s = b.getElementsByTagName(e)[0];\n        s.parentNode.insertBefore(t, s);\n      )(f, b, e, 'https:\/\/www.googletagmanager.com\/gtag\/js?id=AW-877820074', n, t, s);\n    ;<\/p>\n<p>    window.TimesApps = window.TimesApps || ;\n    var TimesApps = window.TimesApps;\n    TimesApps.toiPlusEvents = function(config) \n      var isConfigAvailable = \"toiplus_site_settings\" in f && \"isFBCampaignActive\" in f.toiplus_site_settings && \"isGoogleCampaignActive\" in f.toiplus_site_settings;\n      var isPrimeUser = window.isPrime;\n      if (isConfigAvailable && !isPrimeUser) \n        loadGtagEvents(f.toiplus_site_settings.isGoogleCampaignActive);\n        loadFBEvents(f.toiplus_site_settings.isFBCampaignActive);\n       else \n        var JarvisUrl=\"https:\/\/jarvis.indiatimes.com\/v1\/feeds\/toi_plus\/site_settings\/643526e21443833f0c454615?db_env=published\";\n        window.getFromClient(JarvisUrl, function(config)\n          if (config) \n            loadGtagEvents(config?.isGoogleCampaignActive);\n            loadFBEvents(config?.isFBCampaignActive);<\/p>\n<p>        )<\/p>\n<p>    ;\n  })(\n    window,\n    document,\n    'script',\n  );<\/script><br \/>\n<br \/>[ad_2]<br \/>\n<br \/><a href=\"https:\/\/timesofindia.indiatimes.com\/gadgets-news\/dangerous-apps-with-links-to-india-pakistan-discovered-on-google-play-store\/articleshow\/101135099.cms\" target=\"_blank\" rel=\"noopener\">Source link <\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>[ad_1] Cybersecurity researchers have discovered three apps on Google Play Store that were reportedly used by state-sponsored hackers to collect intelligence from targeted devices. This information includes location data and contact lists of victims. According to a report by Singapore-based cybersecurity company Cyfirma, the operation was attributed to the hacking group &#8220;DoNot\u201d.The hacking group reportedly &#8230; <a title=\"\u2018Dangerous\u2019 spyware apps discovered on Google Play Store\" class=\"read-more\" href=\"https:\/\/bscrackers.com\/?p=2293\" aria-label=\"Read more about \u2018Dangerous\u2019 spyware apps discovered on Google Play Store\">Read more<\/a><\/p>\n","protected":false},"author":1,"featured_media":2294,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[107],"tags":[],"class_list":["post-2293","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-tech"],"_links":{"self":[{"href":"https:\/\/bscrackers.com\/index.php?rest_route=\/wp\/v2\/posts\/2293","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/bscrackers.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/bscrackers.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/bscrackers.com\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/bscrackers.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=2293"}],"version-history":[{"count":0,"href":"https:\/\/bscrackers.com\/index.php?rest_route=\/wp\/v2\/posts\/2293\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/bscrackers.com\/index.php?rest_route=\/wp\/v2\/media\/2294"}],"wp:attachment":[{"href":"https:\/\/bscrackers.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=2293"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/bscrackers.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=2293"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/bscrackers.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=2293"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}