HomeSecurityFake messaging app distributes GravityRAT

Fake messaging app distributes GravityRAT

GravityRAT trojanwith spyware capabilities, is once again infecting devices by hiding inside the seemingly legitimate messaging app SoSafe Chat. In fact, the malicious app claims to offer end-to-end encryption.

GravityRAT

GravityRAT primarily targets Indian users and is distributed by Pakistani hackers.

See also: PhoneSpy: Android spyware campaign targets Korean users

Evidence shows that even in this recent campaign, RAT continues to target “high-profile” individuals in India, such as officers of the Armed Forces.

GravityRAT presents itself as a secure chat app

In 2020, the malware targeted users through an Android app called “Travel Mate Pro.” However, the pandemic limited travel, so cybercriminals had to find a new app to target more users.

The malicious app is now called “SoSafe Chat” and is promoted as a secure messaging app that offers end-to-end encryption.

The site that likely played a role in distributing the app (sosafe.co[.]in) is still up and running, but the download link and registration form are not.

The channel and method of distribution remain unknown, but victims were likely led to the site through malvertising techniques, social media posts, and direct messages to targets.

See also: FakeCop spyware spreads as antivirus in Japan

Spying skills

Once installed on a target's device, GravityRAT-spyware can perform various malicious activities and allow its operators to infiltrate data, spy on the victim, and track their location.

SoSafe Chat spyware messaging app

Here is the list of malicious actions of spyware:

  • Access to SMS, call logs and contacts
  • Change system settings
  • Access to current cellular network information, the victim's phone number and serial number, the status of calls in progress, and a list of Phone Accounts registered on the device
  • Managing files on the device's external storage
  • Audio recording
  • Get network and Wi-Fi information
  • Locating the device location

According to researchers at Cyble, the malicious app asks for many permissions upon installation, but it may seem normal for a messaging app.

See also: The Android app “Smart TV remote” on Google Play is malware

Compared to the 2020 version, GravityRAT has added audio recording, location tracking, and the ability to extract cellular network data.

Before the 2020 version, GravityRAT exclusively targeted Windows. It did not have the ability to target mobile devices.

The most recent attacks, however, show that GravityRAT's operators are constantly evolving it and enhancing its spyware capabilities.

Source: Bleeping Computer

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS