On Tuesday, researchers from ESET said that a wave of attacks carried out by the hacking group BladeHawk is focused on targeting the Kurdish ethnic group through their Android devices.

See also: Hackers target their victims' internet connections
The campaign, which is believed to have been active since at least last March, is abusing Facebook and using the social media platform as a springboard to distribute fake mobile apps.
Researchers have identified six Facebook profiles associated with the BladeHawk group which have now been removed.
While active, these profiles posed as tech figures and Kurdish supporters in order to share links to the group's malicious apps.
See also: The hacker who caused strokes says he stole 600 million crypto "for fun"!
ESET says that at least, the apps - which are hosted on third-party websites and not on Google Play - have been downloaded 1,481 times.
BladeHawk's fake apps were promoted as news services for the Kurdish community. However, they host 888 RAT and SpyNote, two Android-based Remote Access Trojans (RATs) that allow attackers to spy on their victims.
SpyNote was found in only one sample, so it appears that the 888 RAT is currently the main payload of BladeHawk. The commercial Trojan, of which a cracked and free version has been available online since 2019, is capable of executing a total of 42 commands once executed on a target device and a connection to the attacker's command-and-control (C2) server is established.
See also: The largest cryptocurrency theft by hackers! 600 million lost.
The Trojan's functions include taking screenshots and photos, exfiltrating files and sending them to a C2, deleting content, recording audio and monitoring phone calls, intercepting or sending SMS messages, scanning contact lists, stealing GPS location data, and exfiltration of Facebook credentials, among other functions.
Information source: zdnet.com
