New Pakistan-based Cyber Espionage Group’s Year-Long Campaign Targeting Indian Defense Forces with Android Malware
Essential information
- Published
- 06/05/2024 08:47
- Modified
- 06/05/2024 09:29
- Tags
- 2024-05-03 2024-05-04 2024-05-05 2024-05-06 android craxs rat defense espionage india malware pakistan spynote
- Related entities
- 3 observables, 1 intrusion sets (apt), 2 malware, 4 others
Description
CYFIRMA researchers identified an Android malware campaign, active for over a year, targeting Indian defense personnel by an unidentified Pakistan-based cyber espionage group. The threat actor utilized Spynote or a modified version called Craxs Rat, obfuscating the app with high complexity. Through social engineering tactics like impersonating senior officers and distributing the malware via WhatsApp, the group aimed to gain access to victims' contacts, call logs, SMS, and potentially screen monitoring capabilities.