Skip to content
  • Home
  • Science and Technology
  • Edge computing and IoT
  • Cybersecurity
  • Information Technology
  • Artificial Intelligence
  • Advanced Technologies

Transparent Tribe Hackers Distribute CapraRAT via Trojanized Messaging Apps

Posted on March 7, 2023March 9, 2023 By Jerry Simmons

[ad_1]

Mar 07, 2023Ravie LakshmananSpyware / Cyber Espionage

Trojanized Messaging Apps

A suspected Pakistan-aligned advanced persistent threat (APT) group known as Transparent Tribe has been linked to an ongoing cyber espionage campaign targeting Indian and Pakistani Android users with a backdoor called CapraRAT.

“Transparent Tribe distributed the Android CapraRAT backdoor via trojanized secure messaging and calling apps branded as MeetsApp and MeetUp,” ESET said in a report shared with The Hacker News.

As many as 150 victims, likely with military or political leanings, are estimated to have been targeted, with the malware (com.meetup.app) available to download from fake websites that masquerade as the official distribution centers of these apps.

It’s being suspected that the targets are lured through a honeytrap romance scam wherein the threat actor approaches the victims via another platform and persuades them to install the malware-laced apps under the pretext of “secure” messaging and calling.

However, the apps, besides offering the promised functionality, come implanted with CapraRAT, a modified version of the open source AndroRAT that was first documented by Trend Micro in February 2022 and which exhibits overlaps with a Windows malware known as CrimsonRAT.

CapraRAT backdoor

The backdoor is packed with an extensive set of features that allows it to take screenshots and photos, record phone calls and surrounding audio, and exfiltrate other sensitive information. It can also make calls, send SMS messages, and receive commands to download files.

That having said, users are also required to create an account by linking their phone numbers and completing an SMS verification step in order to access the app’s functionalities.

Discover the Latest Malware Evasion Tactics and Prevention Strategies

Ready to bust the 9 most dangerous myths about file-based attacks? Join our upcoming webinar and become a hero in the fight against patient zero infections and zero-day security events!

RESERVE YOUR SEAT

The Slovak cybersecurity company stated the campaign is narrowly targeted and that it found no evidence that indicates the apps were available on the Google Play Store.

Transparent Tribe, also referred to as APT36, Operation C-Major, and Mythic Leopard, was recently attributed to another set of attacks targeting Indian government organizations with malicious versions of a two-factor authentication solution called Kavach.

The findings also arrive weeks after cybersecurity firm ThreatMon detailed a spear-phishing campaign by SideCopy actors targeting Indian government entities with an aim to deploy an updated version of a backdoor known as ReverseRAT.

Found this article interesting? Follow us on Twitter  and LinkedIn to read more exclusive content we post.



[ad_2]

Source_link

Cybersecurity

Post navigation

Previous Post: Edge AI: A survey. Highlights | by Dr Sukhpal Singh Gill | Mar, 2023
Next Post: Fairphone 2 gets its final software update, seven years after original release

Related Posts

Atlassian’s Jira Software Found Vulnerable to Critical Authentication Vulnerability Cybersecurity
Massive AdSense Fraud Campaign Uncovered Cybersecurity
Cacti Servers Under Attack as Majority Fail to Patch Critical Vulnerability Cybersecurity
Only $1 for 1,000 Assets for all of 2023! Cybersecurity
Some Vulnerabilities Date Back to the Last Millennium Cybersecurity
Fortinet Issues Patches for 40 Flaws Affecting FortiWeb, FortiOS, FortiOS, and FortiProxy Cybersecurity

Archives

  • March 2023
  • February 2023
  • January 2023

Categories

  • Advanced Technologies
  • Artificial Intelligence
  • Cybersecurity
  • Edge computing and IoT
  • Information Technology
  • Science and Technology

Meta

  • Log in
  • Entries feed
  • Comments feed
  • WordPress.org

Recent Posts

  • New Critical Flaw in FortiOS and FortiProxy Could Give Hackers Remote Access
  • Why cars running on e-fuel can’t replace EVs
  • Google’s cloud gaming ambitions died with Stadia, exec reveals
  • Wii U memory errors are a new problem for old game consoles
  • Silvergate has collapsed – The Verge

Recent Comments

    AndNews.

    Powered by PressBook Masonry Dark