Android-based espionage campaign in the Middle East targets military data
Full article741 words · extracted from cyberscoop.com · click to collapse
Get our latest cybersecurity news first on Google.
Malware analyzed by Trend Micro sucks up a target phone’s call logs and records.
A newly uncovered espionage campaign in the Middle East has infected more than 660 Android phones, and much of the stolen data appears to be “military-related,” researchers from cybersecurity company Trend Micro said Tuesday.
The malware in question is highly invasive, posing as popular news and lifestyle apps to suck up a target phone’s call logs and records, text messages, and storage and memory details, among other data. Attackers aren’t using the Google Play store, a sometimes popular receptacle for malicious apps. Instead, the host website for the malware is being promoted via social media channels, according to Trend Micro. One feature of the malware even allows the operator to take a photo from an infected phone when the device’s owner “wakes” it in locked mode.
Analysts did not pin the so-called “Bouncing Golf” spying operation, which is ongoing, on any group or person, but said the structure of the code used and the data targeted share similarities with a spying campaign reported last year by cybersecurity company Check Point. The prime suspect in that campaign was the Iranian government, Check Point said.
Whoever they are, the operators of the newly documented malware have looked to mask their origins. The contact information they used to register their malware-distributing domains is hidden, Trend Micro said. The IP addresses of their command-and-control server span France, Germany, Russia and other countries.
The researchers did not elaborate on the “military-related” data that was pilfered, other than to say it included images and documents. The limited scope of infected Android phones isn’t surprising given this is a spying operation, “but we also expect it to increase or even diversify in terms of distribution,” the researchers wrote in a blog post.
“[W]e expect more cyber-espionage campaigns targeting the mobile platform given its ubiquity, employing tried-and-tested techniques to lure unwitting users,” they added.
Google has sought to crack down on the abuse of Android apps by sanitizing the Google Play store, and by restricting the use of text and call log permissions in apps. But hackers have kept up their innovation in response.
Researchers at cybersecurity company ESET said Monday they had found malicious Android apps capable of getting around Google’s restrictions to steal passwords.
In the case of the Bouncing Golf espionage campaign, some of the malicious apps have names that are similar to legitimate apps in the Google Play store – a possible attempt to make them seem legitimate, Trend Micro researchers told CyberScoop.
More Scoops
Interpol leads cybercrime crackdown across 13 countries in Middle East, North Africa
Operation Ramz resulted in 201 arrests and disrupted phishing services, malware and financial scams.
Hack-for-hire spyware campaign targets journalists in Middle East, North Africa
Android spyware disguised as legitimate messaging apps targets UAE victims, researchers reveal
Latest Podcasts
Government
FBI officials say AI is bolstering adversaries, emphasizing need to focus on cyber basics, patching
Feds accuse China of ‘systematic’ distillation of U.S. AI models
CIA’s Michael Ellis says cyber intelligence is changing how the agency operates
Jail time for Maine child in 764 marks turning point in federal law enforcement
Technology
Threats
Policy
Whistleblower says USPS deploying new, ‘untested’ IT systems governing mail-in ballots
‘Watershed 250’ test program in Texas looks to private sector for water cybersecurity help
Former sexual abuse victims say Grok used their images, videos to train deepfake capabilities
Cyber threats nudge Trump to sign executive order on foreign equipment in U.S. energy infrastructure
Text extracted automatically; images, tables and formatting may be missing. Original: https://cyberscoop.com/android-espionage-campaign-middle-east-trend-micro/