Beware of Malicious Android Apps on Google Play Store

TL;DR Summary
Three Android apps on Google Play, attributed to the Indian hacking group DoNot, were used to collect intelligence from targeted devices. The apps, including a fake VPN and chat app, request risky permissions during installation to exfiltrate information such as location data and contact lists to the threat actor. The apps' code base was taken directly from legitimate products, and the attackers have abandoned phishing emails in favor of spear messaging attacks via WhatsApp and Telegram. Little is known about the targets, except that they are based in Pakistan.
- Android spyware camouflaged as VPN, chat apps on Google Play BleepingComputer
- Rogue Android Apps Target Pakistani Individuals in Sophisticated Espionage Campaign The Hacker News
- Android spyware found hiding out in Play Store; delete these two apps now! PhoneArena
- CYFIRMA Cybersecurity Firm Finds Malicious Android Apps on Google Play Store gizmochina
- Massive Adware infestation: Over 60,000 android apps pose threat to users' privacy HT Tech
- View Full Coverage on Google News
Reading Insights
Total Reads
0
Unique Readers
14
Time Saved
2 min
vs 3 min read
Condensed
81%
469 → 89 words
Want the full story? Read the original article
Read on BleepingComputer