HomeSecurityAndroid malware GravityRAT steals your WhatsApp backups

Android malware GravityRAT steals your WhatsApp backups

A new Android malware campaign spreading the latest version of GravityRAT has been ongoing since August 2020, infecting mobile devices with a trojanized chat app called “BingeChat” that attempts to steal data from victims’ devices.

See also: DogeRAT Trojan mainly targets Android users

GravityRAT

According to researcher Lukas Stefanko from ESET, who analyzed a sample after a tip he received from MalwareHunterTeam, one of the notable new additions detected in the latest version of GravityRAT is the ability to steal WhatsApp backup files.

WhatsApp backups are created to help users transfer their message history, media files, and data to new devices. They may contain sensitive data, such as text, videos, photos, documents, and more – all in an unencrypted format.

GravityRAT has been active since at least 2015, but began targeting Android for the first time in 2020. Its SpaceCobra operators use the spyware exclusively and in narrowly targeted operations.

See also: SpinOk Android malware found in other popular apps

Current Android campaign

The spyware spreads under the name “BingeChat,” purporting to be an end-to-end encrypted chat application with a simple interface but advanced features.

GravityRAT

ESET says the app is delivered via “bingechat.net” and possibly other domains or distribution channels, but download is invitation-based, requiring visitors to enter valid credentials or register a new account.

While registrations are currently closed, this method only allows them to distribute malicious applications to targeted individuals, making it more difficult for researchers to access a copy for analysis.

Pushing malicious Android APKs to targets is a tactic used by GravityRAT operators again in 2021, using a chat app called “SoSafe” and, before that, another called “Travel Mate Pro.”.

Stefaneko found that the app is a trojanized version of OMEMO IM, a legitimate open-source instant messaging app for Android.

Looking further, the ESET found that the SpaceCobra threat actor had used OMEMO IM as the basis for another fake application called “Chatico”, which was distributed to targets in the summer of 2022 via the now-defunct website “chatico.co.uk”.

Android malware GravityRAT steals your WhatsApp backups

See also: Over 60,000 Android apps infected devices with adware

GravityRAT Features

BingeChat requests dangerous permissions upon installation on the target device, including access to contacts, location, phone, SMS, storage, call logs, camera , and microphone.

These are standard permissions for instant messaging apps, so they are unlikely to arouse suspicion or seem abnormal to the victim.

Before the user signs up for BingeChat, the app sends call logs, contact lists, SMS messages, device location, and basic device information to a threat actor's command and control (C2) server.

Additionally, multimedia and document files of jpg, jpeg, log, png, PNG, JPG, JPEG, txt, pdf, xml, doc, xls, xlsx, ppt, pptx, docx, opus, crypt14, crypt12, crypt13, crypt18 and crypt32 types are also stolen.

The “.crypt” file extensions correspond to the WhatsApp Messenger backups mentioned earlier.

GravityRAT

Another notable new feature of GravityRAT is its ability to receive three commands from the C2: “delete all files” (of a specific extension), “delete all contacts” and “delete all call logs”.

While SpaceCobra's campaigns are highly targeted and typically focus on India, all Android users should avoid downloading APKs outside of Google Play and be wary of dangerous permission requests when installing any app.

Information source: bleepingcomputer.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Teo Ehc
Teo Ehchttps://www.secnews.gr
Be the limited edition.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS