ESET discovers targeted attack via fake messaging apps, available on web and Google Play

ESET researchers have discovered an active espionage campaign named eXotic Visit, targeting Android users with apps primarily posing as messaging services. An active and targeted Android espionage campaign, eXotic Visit, started in late 2021 and mainly impersonates messaging apps that are distributed through dedicated websites and Google Play. The region of interest seems to be … More ESET discovers targeted attack via fake messaging apps, available on web and Google Play

ESET Research discovers espionage apps utilizing romance scams

ESET Research discovered a new cyberespionage campaign that, with a high level of confidence, ESET attributes to the Patchwork APT group. The campaign leveraged Google Play to distribute six malicious apps bundled with VajraSpy RAT code; six more were distributed in the wild. The apps on Google Play reached over 1,400 installs and are still … More ESET Research discovers espionage apps utilizing romance scams

These aren’t the Androids you should be looking for

You may get more than you bargained for when you buy a budget-friendly smartphone and forgo safeguards baked into Google Play. When shopping for a new smartphone, you’re likely to look for the best bang for your buck. If you’re on the hunt for a top-of-the-range device but aren’t keen on paying top dollar for … More These aren’t the Androids you should be looking for

Loan sharks use Android apps to reach new depths

Beware of predatory fin(tech): ESET researchers describe the growth of deceptive loan apps for Android and techniques they use to circumvent Google Play Deceptive SpyLoan apps analyzed by ESET researchers request various kinds of sensitive information from their users and exfiltrate it to the attackers’ servers. This data is then used to harass and blackmail … More Loan sharks use Android apps to reach new depths

ESET Research: Spy apps by the GREF group pose as Signal and Telegram; attack users in Europe and the US

ESET researchers have identified two active campaigns targeting Android users, where the threat actors behind the tools for Telegram and Signal are attributed to the APT group GREF. Most likely active since July 2020 and since July 2022, respectively for each malicious app, the campaigns have distributed the Android BadBazaar espionage code through the Google … More ESET Research: Spy apps by the GREF group pose as Signal and Telegram; attack users in Europe and the US