ZeroHour
CyberScooppublished ()ingested @snlyngaas

Android-based espionage campaign in the Middle East targets military data

criticalThreat actor exploited in the wildimportance 60
Full article741 words · extracted from cyberscoop.com · click to collapse
Skip to main content

Get our latest cybersecurity news first on Google.

Click here!

Malware analyzed by Trend Micro sucks up a target phone’s call logs and records.

Android mobile phone, Samsung Galaxy S10, Google Play Store
(Kārlis Dambrāns / Flickr)

A newly uncovered espionage campaign in the Middle East has infected more than 660 Android phones, and much of the stolen data appears to be “military-related,” researchers from cybersecurity company Trend Micro said Tuesday.

The malware in question is highly invasive, posing as popular news and lifestyle apps to suck up a target phone’s call logs and records, text messages, and storage and memory details, among other data. Attackers aren’t using the Google Play store, a sometimes popular receptacle for malicious apps. Instead, the host website for the malware is being promoted via social media channels, according to Trend Micro. One feature of the malware even allows the operator to take a photo from an infected phone when the device’s owner “wakes” it in locked mode.

Analysts did not pin the so-called “Bouncing Golf” spying operation, which is ongoing, on any group or person, but said the structure of the code used and the data targeted share similarities with a spying campaign reported last year by cybersecurity company Check Point. The prime suspect in that campaign was the Iranian government, Check Point said.

Whoever they are, the operators of the newly documented malware have looked to mask their origins. The contact information they used to register their malware-distributing domains is hidden, Trend Micro said. The IP addresses of their command-and-control server span France, Germany, Russia and other countries.

The researchers did not elaborate on the “military-related” data that was pilfered, other than to say it included images and documents. The limited scope of infected Android phones isn’t surprising given this is a spying operation, “but we also expect it to increase or even diversify in terms of distribution,” the researchers wrote in a blog post.

“[W]e expect more cyber-espionage campaigns targeting the mobile platform given its ubiquity, employing tried-and-tested techniques to lure unwitting users,” they added.

Google has sought to crack down on the abuse of Android apps by sanitizing the Google Play store, and by restricting the use of text and call log permissions in apps. But hackers have kept up their innovation in response.

Researchers at cybersecurity company ESET said Monday they had found malicious Android apps capable of getting around Google’s restrictions to steal passwords.

In the case of the Bouncing Golf espionage campaign, some of the malicious apps have names that are similar to legitimate apps in the Google Play store – a possible attempt to make them seem legitimate, Trend Micro researchers told CyberScoop.

More Scoops

This photograph taken in Lyon, eastern France, on September 5, 2023 shows the entrance of the International Criminal Police Organization headquarters, known as Interpol. (Photo by OLIVIER CHASSIGNOLE/AFP via Getty Images)

Interpol leads cybercrime crackdown across 13 countries in Middle East, North Africa

Operation Ramz resulted in 201 arrests and disrupted phishing services, malware and financial scams.

Malte Mueller, Getty Images

Hack-for-hire spyware campaign targets journalists in Middle East, North Africa

The Signal encrypted messaging application is seen on a mobile device in this illustration photo taken in Warsaw, Poland on March 25, 2025. (Photo by Jaap Arriens/NurPhoto)

Android spyware disguised as legitimate messaging apps targets UAE victims, researchers reveal

Latest Podcasts

Text extracted automatically; images, tables and formatting may be missing. Original: https://cyberscoop.com/android-espionage-campaign-middle-east-trend-micro/