HomeSecuritySideWinder hackers install fake Android VPN app on Google Play Store

SideWinder hackers install fake Android VPN app on Google Play Store

The phishing campaigns attributed to an advanced threat actor called SideWinder included a fake VPN app for Android devices published on the Google Play Store along with a custom tool that filters victims for better targeting.

SideWinder is an APT group that has been active since at least 2012 and is believed to be an Indian-origin threat actor with a relatively high level of sophistication.

See also: Ransomware attacks: It takes 4 days to encrypt systems

SideWinder

Kaspersky security researchers have attributed nearly 1,000 attacks to this group over the past two years. Among its primary targets are organizations in Pakistan, China, Nepal , and Afghanistan.

See also: Abuse of Telegram's blogging platform in phishing attacks

The adversary relies on a fairly large infrastructure, which includes more than 92 IP addresses, mainly for phishing attacks, hosting a large number of domains and subdomains used as command and control servers.

SideWinder hackers install fake Android VPN app on Google Play Store

A recent phishing campaign attributed to the SideWinder group (also known as RattleSnake, Razor Tiger, T-APT-04, APT-C-17, Hardcore Nationalist) targeted organizations in Pakistan in both the public and private sectors.

Researchers at cybersecurity firm Group-IB earlier this year discovered a phishing document that lures victims with a document suggesting “a formal discussion on the impact of the US from Afghanistan on maritime security.”

SideWinder

In a report shared with BleepingComputer, Group-IB says that the SideWinder agent has previously been observed cloning a government website to steal user credentials.

The recent phishing also used this method against targets, as the hacker created multiple websites that mimicked legitimate Pakistani government domains:

  • finance.pakgov[.]net
  • vpn.pakgov[.]net
  • csd.pakgov[.]net
  • hajj.pakgov[.]net
  • nadra.pakgov[.]net
  • pt.pakgov[.]net
  • flix.pakgov[.]net
  • covid.pakgov[.]net

During the investigation, researchers discovered a phishing link that redirected to the legitimate domain “securevpn.com.” Its purpose remains unclear, but it could be to select targets of interest and redirect them to a malicious site.

Another link discovered by Group-IB and taken from Google Play, the official Android app store, is a fake version of the “Secure VPN” app, which is still available on Google Play at the time of writing.

SideWinder hackers install fake Android VPN app on Google Play Store

Researchers note that the description available for the fake SideWinder Secure VPN app has been copied from the legitimate NordVPN app.

At runtime, the fake Secure VPN application makes several requests to two domains that likely belong to the attacker, but were unavailable during the investigation, and a request to the root directory is redirected to the legitimate NordVPN domain.

Unfortunately, researchers were unable to confirm the purpose of the fake VPN app or whether it was malicious or not. However, SideWinder has used fake apps on Google Play in the past, as previous research by Trend Micro showed.

The list of actions that previous fake applications from SideWinder could perform includes collecting and sending to the command and control server information such as:

  • Location
  • Battery status
  • Files on the device
  • List of installed applications
  • Device information
  • Sensor information
  • Camera information
  • Screenshot
  • Account
  • Wi-Fi information
  • WeChat, Outlook, Twitter, Yahoo Mail, Facebook, Gmail , and Chrome

Their applications are able to collect a number of parameters on targeted hosts and send the information back to C2 .

Group-IB found that the adversary used a custom tool recently added to its arsenal, which is tracked internally by Group-IB as SideWinder.AntiBot.Script.

If the script detects a visitor from an IP in Pakistan, it redirects to a malicious location. The following parameters are checked to determine whether a visitor is a potential target or not:

  • Geographical location
  • Operating system version
  • User agent data
  • System language settings

It can also determine the number of logical processors in the system and the video card used by the host, as well as access the credentials container in the web browser, which can return saved passwords.

Checking the video card is likely to determine whether the host is being used for malware analysis purposes, as it is compared to the device's screen.

Another function in the script, the most important one, is used to serve a malicious file and redirect a non-interest target to a legitimate resource.

Based on its findings, Group-IB estimates that SideWinder's infrastructure is widely used to deploy new command and control servers to support phishing activity.

Information source: bleepingcomputer.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Teo Ehc
Teo Ehchttps://www.secnews.gr
Be the limited edition.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS