According to CYFIRMA researchers, the Indian APT hacking group 'Bahamut' is using a fake Android app called 'SafeChat' to infect devices with spyware, stealing call logs, texts, and GPS locations. Researchers believe spyware is a variant of Coverlm that is capable of targeting communication apps like Telegram, Signal, WhatsApp, Viber, and Facebook Messenger. CYFIRMA's analysts stated that in the campaign, the APT group sends spear phishing messages with malicious payloads via WhatsApp and targets individuals from South Asia by persuading them to install the app under the pretext of enhanced security. Researchers while analysis found similarities between Bahamut and another Indian group, DoNot APT, which previously infected Google Play with fake chat apps. During the investigation, researchers discovered that Safe Chat includes a deceptive UI and user registration process that make it appear as a legitimate messaging app, but instead it is spyware. Once installed, the application requests access to the victim's contacts, SMS, call logs, phone storage, and GPS location information. To ensure that it runs continuously, the app additionally requests to be excluded from Android's battery optimisation. Furthermore, the app is designed to communicate with other running chat applications through the use of intents and the OPEN_DOCUMENT_TREE permission. To prevent interception, a data exfiltration module sends stolen data to the attacker's C2 server via port 2053 after encrypting it with RSA, ECB, and OAEPPadding, which uses a letsencrypt certificate.
Security researchers have revealed a highly sophisticated Linux rootkit named Singularity, which can bypass Elastic Security’s endpoint detection and response (EDR) mechanisms. T...
The Symantec Threat Hunter Team has uncovered two major cyber intrusions targeting Ukrainian organizations, attributed to Russian-aligned threat actors. Active from late June to Au...
Attackers based in China are taking advantage of vulnerabilities in Cisco ASA, which is widely used by governments and big organizations around the world. According to Palo Alto Ne...