
Beware of Malicious Android Apps on Google Play Store
Three Android apps on Google Play, attributed to the Indian hacking group DoNot, were used to collect intelligence from targeted devices. The apps, including a fake VPN and chat app, request risky permissions during installation to exfiltrate information such as location data and contact lists to the threat actor. The apps' code base was taken directly from legitimate products, and the attackers have abandoned phishing emails in favor of spear messaging attacks via WhatsApp and Telegram. Little is known about the targets, except that they are based in Pakistan.