Tag: VajraSpy

Patchwork Using Romance Scam Lures to Infect Android Devices with VajraSpy Malware
News

Patchwork Using Romance Scam Lures to Infect Android Devices with VajraSpy Malware

The threat actor Patchwork most likely lured victims into Pakistan and India using romance scams, then infected their Android handsets with the VajraSpy remote access trojan. The slovak cybersecurity company ESET reported that it has discovered 12 espionage apps, six of which could be downloaded from the Google Play Store and were downloaded over 1,400 times in total between April 2021 and March 2023. According to security researcher Lukáš Štefanko, "VajraSpy has a range of espionage functionalities that can be expanded based on the permissions granted to the app bundled with its code." It steals contacts, files, call logs, and SMS messages, but some of its implementations can even extract WhatsApp and Signal messages read more Patchwork Using Romance Scam Lures to Infect Androi...
More Android apps riddled with malware spotted on Google Play
News

More Android apps riddled with malware spotted on Google Play

Twelve malicious applications were discovered to include the Android remote access trojan (RAT) VajraSpy; six of these applications were available on Google Play between April 1, 2021, and September 10, 2023. The malicious apps are still available on third-party app stores after being deleted from Google Play. They pose as news or messaging apps. Installing the apps resulted in the users' becoming infected with VajraSpy, which gave the virus access to their contacts, messages, and, depending on the permissions allowed, even phone records. The campaign's operators, according to ESET researchers who found it, are the Patchwork APT organization, which has been operating since at least late 2015 read more More Android apps riddled with malware spotted on Google Play. Get up to dat...