HomeSecurityNew APT42 group develops custom Android spyware

New APT42 group develops custom Android spyware

A new Iranian-sponsored hacking group known as APT42 has been discovered that uses a custom Android malware to spy on targets of interest.

New APT42 group develops custom Android spyware

The cybersecurity firm has collected enough evidence to determine that the APT42 group is an Iran-backed threat actor engaged in cyberespionage against individuals and organizations of particular interest to the Iranian government.

See also: HP: Fixes bug in pre-installed Support Assistant tool

The first signs of APT42 activity date back seven years and revolve around long-running spear-phishing targeting government officials, politicians, journalists, academics around the world, and Iranian dissidents.

Hackers' goal is to steal account credentials. However, in many cases, they also develop a customized strain of Android malware with the ability to track victims, access device storage, and extract communication data.

Campaigns and goals

According to Mandiant, which discovered APT42's activities, the group has carried out at least 30 operations in 14 countries since 2015.

New APT42 group develops custom Android spyware

The group has changed targets several times to suit changing intelligence gathering interests. For example, in 2020, APT42 used phishing emails impersonating an Oxford University vaccinologist to target foreign pharmaceutical products.

New APT42 group develops custom Android spyware

In 2021, the APT42 group used compromised email addresses from US media organizations to target victims with fake interview, interacting with them for 37 days before hitting them with a credential harvesting page.

APT42

Most recently, in February 2022, hackers impersonated a British news agency to target political science in Belgium and the United Arab Emirates.

In most cases, hackers aimed to collect credentials by directing their victims to phishing pages designed to appear as legitimate login portals.

See also: North Face: 200,000 accounts compromised through credential stuffing

They do this either by sending shortened links or an attached PDF containing buttons that lead to credential collection pages that can also steal MFA codes.

APT42

Android malware

The mobile malware strain used in APT42 campaigns helps the threat actor closely monitor its most high-interest targets (phone calls, incoming SMS, and more).

Mandiant says the Android spyware is primarily spread to Iranian targets via SMS messages containing links to a messaging app or VPN that can help bypass government-imposed restrictions.

APT42

However, Mandiant says it is also discovering landing pages for downloading IM apps in Arabic, so the threat actors may have developed the Android malware outside of Iran as well.

The APT42 group uses a rich set of lightweight custom malware on Windows systems to establish a base and steal credentials that will allow them to escalate privileges and conduct network.

See also: Albania blames Iran for July cyberattack and breaks diplomatic relations

For lateral movement, hackers send phishing emails to colleagues of the compromised user. At the same time, presence on newly compromised is ensured by adding scheduled tasks and new Windows registry keys.

APT42

Links to ransomware

Mandiant highlights the connection between APT42 group TTPs and ransomware using BitLocker ,reported in November 2021 by Microsoft.

Mandiant now says there is sufficient technical evidence to link the APT42 attacks, along with the APT35 group.

Finally, Mandiant estimated (with all reservations) that APT42 and APT35 are both operations of the IRGC (Islamic Revolutionary Guard Corps), which the US designates as a terrorist organization.

Information source: bleepingcomputer.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Teo Ehc
Teo Ehchttps://www.secnews.gr
Be the limited edition.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS