216.73.216.6

Mobile spyware campaign impersonates Israel's Red Alert rocket warning system

· Published 06/03/2026 15:21 · Modified 09/03/2026 10:30

Export JSON

Essential information

Published
06/03/2026 15:21
Modified
09/03/2026 10:30
Tags
2026-03-06 android certificate spoofing red alert sms social engineering spyware
Related entities
3 observables, 1 intrusion sets (apt), 1 malware, 3 others

Description

A targeted campaign has been identified distributing a trojanized version of the rocket warning app to Israeli users via messages impersonating official Home Front Command communications. The malicious app retains full rocket alert functionality while running malicious code in the background. It bypasses security checks through and runtime manipulation. Once installed, the malware collects sensitive data including messages, contacts, location data, device accounts, and installed applications. The stolen data is transmitted to a remote command-and-control server. This campaign exploits user trust in emergency services during periods of geopolitical tension, combining with mobile espionage for maximum impact.

External references