New Version of Android GravityRAT Spyware Targets WhatsApp Backups

An updated version of the Android GravityRAT spyware that targets WhatsApp backups has been discovered by ESET security researchers.

ESET malware researcher Lucas Stefanko said in an advisory published by the company on Thursday that the new variant of the malware is being distributed via two messaging apps, BingeChat and Chatico.

GravityRAT is a remote access tool that has been observed since at least 2015. It was previously used in targeted attacks against India.

It is available for Windows, Android and macOS platforms, but its origins and the group behind it (known internally as SpaceCobra inside ESET) remain unknown.

This new variant, observed by ESET, began around August 2022 and is specifically aimed at gaining unauthorized access to WhatsApp backups, potentially compromising sensitive personal information.

Read more about malware targeting WhatsApp: Telegram, WhatsApp trojanized to target cryptocurrency wallets

BingeChat and Chatico, available on the Google Play store, have been repurposed to carry out these malicious activities, evading initial suspicions.

“A trojanized BingeChat app can be downloaded from a website that serves as a free messaging and file-sharing service,” Stefanko wrote.

The malware’s capabilities include exfiltrating user data from compromised devices and remotely issuing commands to delete information.

Notably, the malicious app also offers legitimate chat functionality based on the open-source OMEMO instant messenger app.

BingeChat is likely to continue, but the Chatico app is no longer active, ESET said.

The campaign’s discovery came after the company’s security researchers did. warned By MalwareHunterTeam, they shared hashes of GravityRAT samples on Twitter.

“According to ESET telemetry, users in India were targeted with the updated Chatico version of the RAT, similar to previously documented SpaceCobra campaigns,” Stefanko explained.

“BingeChat versions are distributed through websites that require registration and are only available if the attacker is expected to visit a specific IP address, location, custom URL, or visit a specific victim within a specific time period. Either way, we believe this campaign is highly targeted.”

ESET advisories contain indicators of compromise (IoCs) for new threats.

Editorial image credit: Worawee Meepian / Shutterstock.com



Source link

Leave a Reply

Your email address will not be published. Required fields are marked *