The Bahamut hacking group , which has been active since 2017, has created a fake VPN software for Android that is a trojanized version (spyware) of legitimate software, such as SoftVPN and OpenVPN. A VPN, or Virtual Private Network, creates a secure connection between your device and the internet. This connection allows you to browse the internet anonymously and securely, without your data being compromised . Many people turn to VPNs to enhance their security, which is why cybercriminals are taking advantage of it.

Researchers say the campaign was “highly targeted” and aimed to steal contact information, data , device location data, as well as messages from multiple apps.
See also: New SandStrike spyware infects Android devices via malicious VPN app
Fake VPN apps mimic legitimate apps
The operation was carried out by a group referred to as Bahamut, which is likely a group that provides hack-for-hire services.
According to ESET malware analyst Lukas Stetanko, the SoftVPN and OpenVPN apps for Android have been repackaged with malicious code that enables spyware functionality.
By doing this, the attacker ensured that the apps would still offer VPN capabilities to the victim, while also stealing sensitive information from their mobile device.
Stefanko explains that the fake VPN app can steal contacts, call logs, location details, SMS, eavesdrop on conversations on messaging apps like Signal, Viber, WhatsApp , and Telegram, as well as collect a list of files accessible on external storage.
In order to conceal their plan and for greater credibility, Bahamut took the name of an existing VPN service, SecureVPN, and created a fake website [thesecurevpn] to distribute their malicious application.

ESET researcher discovered eight versions of the Bahamut group's spy VPN application
See also: Online spoofing service iSpoof: Police arrested 146 people
All of the fake apps included code that had only appeared in earlier Bahamut operations.
It is worth noting that none of the trojanized VPN versions were available through Google Play, the official Android app store .
The method for the first stage of distribution is unknown, but it could be anything from a phishing email, to a message on social media or another communication app.
See also: Hodlnaut crypto company accused of fraud
Information about the Bahamut group came to light in 2017, when some journalists published an article revealing that the group was targeting Middle Eastern human rights activists.

Given that Bahamut relies heavily on public tools and frequently changes its tactics, it would be difficult to connect the group to other threat actors. Furthermore, their targets are spread across different regions.
However, in an extensive report on Bahamut published by BlackBerry researchers in 2020, it was noted that the group appears to be well-funded and equipped.
Source: www.bleepingcomputer.com
