HomeSecuritySurveillance app infects both iOS and Android devices

Surveillance app infects both iOS and Android devices

devices

A recent discovery by cybersecurity researchers has uncovered a mobile surveillance feature that secretly eavesdrops on data from both iOS and Android. According to the researchers, it is likely to be “lawful intercept” software, which is used by law enforcement and governments.

The version of the malware that attacks Android devices, dubbed Exodus, has been in development for the past five years. It appears to have been distributed via apps disguised as service apps from Italian providers. Nearly 25 of these apps are available on Google Play. Researchers believe that hundreds or even thousands of devices have been affected.

The three stages involved in malware are:

First stage: collects basic information about the device, such as the IMEI and phone number, and sends it to a command and control server. Second stage: installs itself almost immediately after the phone is infected by the first stage and also communicates with a server. The second stage consists of several binary packages that implement most of the surveillance capabilities. In addition, they can take advantage of the capabilities available on the device. A third stage allows Exodus to gain root access to the infected device, usually by using a vulnerability known as DirtyCOW. Once fully installed, Exodus can achieve extensive surveillance, such as:

  • Retrieve list of installed applications
  • Recording the environment using the built-in microphone in 3gp format
  • Recover browsing history and bookmarks from Chrome and SBrowser (the browser that comes with Samsung phones)
  • Export events from the Calendar app
  • Export the call log
  • Record phone calls in 3gp format
  • Taking photos with the built-in camera
  • BTS information collection
  • Exporting the address book
  • Export your contact list from the Facebook app
  • Export logs from Facebook Messenger conversations
  • Capture screenshots of any foreground application
  • Extracting information into images from the Report
  • Export information from the Gmail app
  • Data entry from the IMO Messenger application
  • Export call logs, contacts, and messages from the Skype app
  • Recover all SMS
  • Export messages and encryption key from the Telegram app
  • Data entry from the Viber messenger app
  • Export logs from WhatsApp
  • Recover media exchanged via WhatsApp
  • Extract the Wi-Fi network password
  • Extract data from WeChat app
  • Export the phone's GPS coordinates

The corresponding iPhone malware was distributed via phishing websites.

The iOS version was installed through Apple’s Enterprise Developer Program, which allows organizations to distribute internal apps to employees or members without using the iOS App Store. The apps were disguised as service apps and asked users to “keep the app installed on their device and stay connected over Wi-Fi.”

The infected iPhones are linked to domains and IP addresses belonging to Connexxa. Connexxa is the same Italian company whose domains and IP addresses were used by Exodus.

Researchers said a company called eSurv SRL is also involved in the malware distribution efforts. eSurv Software was once a business unit of Connexxa, which in 2016 was sold along with the brand to eSurv SRL.

It is unclear how many iPhone devices have been infected. The iOS variant of the malware is not as sophisticated as Exodus. Unlike Exodus, the iOS version was not observed to exploit vulnerabilities. Instead, it relied on documented programming interfaces. However, it was able to obtain a variety of sensitive data, including:

  • Contacts
  • Recordings
  • Photos
  • Video
  • Location via GPS
  • Device information

Because the iOS variant relied on APIs provided by Apple, the malware provided users with notifications with some telltale signs that their sensitive data was being monitored.

The Lookout researchers reported their findings to Apple, and the company revoked the enterprise certificate. The revocation prevents the apps from installing on new iPhones and causes them to stop working on infected devices. The researchers who discovered Exodus also reported their findings to Google, and the company removed nearly 25 apps from Google Play.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr/politiki-syntaxis/
Member of the Editorial Team of SecNews. He writes about cybersecurity, online fraud, privacy and technology. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS