An Android RAT targets Telegram Users
Essential information
- Published
- 28/06/2024 14:49
- Modified
- 28/06/2024 14:57
- Tags
- 2024-06-28 android keylogger phishing rat spymax surveillance
- Related entities
- 4 observables, 10 techniques (mitre), 1 malware
Description
This analysis discusses SpyMax, a Remote Access Trojan (RAT) that targets Android devices and specifically aims at obtaining data from Telegram users. It employs phishing techniques to trick victims into installing a malicious application disguised as the legitimate Telegram app. Once installed, SpyMax gains extensive permissions, gathers sensitive information like keystrokes and location data, and transmits it to a remote command-and-control server. The malware also receives commands and additional payloads from the server, enabling remote control of the compromised device. The report outlines the technical details of SpyMax's operations, including its obfuscation methods, data exfiltration process, and communication with the command-and-control infrastructure.