HomeSecurityAndroid Spyware Targets Military and Government Security Personnel!

Android Spyware Targets Military and Government Security Personnel!

Saudi security researchers who applied for jobs with the Saudi Arabian government and military unwittingly installed spyware on their Android devices.

Intel Security's Mobile Research division came across a job portal in Saudi Arabia that was promoting a private chat app for Android devices through its website.

Android Spyware Targets Military and Government Security Personnel!

Users who visited the ksa-sef[.]com portal were looking for security-related jobs working with the Saudi Arabian government and military and wanted to install the application, they would be infected with the Android/ChatSpy spyware.

This malware did not have a functional chat interface, would immediately hide its icon after installation, start collecting data about the device, and then register the victim with a C&C (command and control) server.

After a while, Android/SpyChat would also start transferring stolen data to the server, including details such as the user's contact list, SMS, browser history, call logs, and basic hardware . Additionally, if needed, the spyware would be able to forward the victim's phone calls to a desired phone number.

ksa-sef

Intel researchers say the threat behind this campaign was hosted in the C&C infrastructure on the same server as the job portal, a fact that was reported to the Saudi CERT team.

Considering the highly sensitive information a security professional would handle on a daily basis in the Saudi Arabian government and military, this is undoubtedly a cyber-espionage campaign.

Intel staff did not attempt to attribute responsibility for the attacks to any specific nation-state, but in the past, Iran has been accused of similar campaigns against Saudi Arabia, such as in an operation known as OilRig.

Below is a quote from Intel Security's Yukihiro Okutomi, who sums up the malware in a way that really characterizes it:

“Despite the fact that the spyware works cleanly and quietly, the application code is of poor quality. The spyware contains “spy” in the package name and the hardcoded SMS to the attacker contains the word “victim” in plain text. The spyware uses an open-source “call-recorder-for-android” and is available on GitHub, to implement the voice recording function. With such sloppy coding, the spyware must have been hastily created by a “child script.””

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS