A particularly disturbing Android spyware, dubbed GhostChat, highlights the growing convergence of social engineering and advanced surveillance techniques. The attack, which primarily targets users in Pakistan, relies on romance scams and fake dating appsto steal personal data and fully track mobile devices.

The GhostChat malware presents itself as a legitimate chat application, while in the background it operates as spyware , capable of collecting files, contacts, and user activity without any obvious signs.
The return of romance scams in a mobile environment
Romance scams are not a new phenomenon, but this campaign demonstrates that cybercriminals are adapting their techniques to modern mobile ecosystems. Instead of simple conversations on social networks, the deception is now delivered directly to the victim's device via malicious applications.
See also: ShinyHunters: New vishing campaign with hundreds of targets
This particular attack was detected in September 2025, when a suspicious Android app was uploaded to VirusTotal by a user in Pakistan, piqued the interest of cybersecurity researchers.
GhostChat: Disguise as a dating app
GhostChat appears as an app titled “Dating Apps without payment,” using the icon of a legitimate app available on Google Play. Despite this design, the malicious version was never hosted on an official app store.
Instead, victims are asked to install the APK file manually, enabling the option to install apps from unknown sources — a critical step that bypasses Google Play Protect during the initial infection stage.
A level of deception that stands out
Welivesecurity analysts point out that GhostChat stands out for its unusually elaborate deception mechanism. The app displays 14 female dating profiles , all locked, requiring a special password to unlock.

These codes are embedded in the malicious code and distributed with the application, creating the illusion of limited or “exclusive” access. In this way, victims are convinced that they are participating in a private dating platform.
Redirect to WhatsApp and enhance reliability
After entering the correct code, the user is automatically redirected to WhatsApp and contacted by numbers controlled by the attackers. All numbers use Pakistani codes, which adds to the credibility of the scam locally.
While the victim believes they are chatting with real people, the spyware is already activated in the background.
See also: Microsoft 365: Outlook add-ins abused to steal email data
Full device monitoring
GhostChat immediately begins collecting critical information, such as:
- unique device identifiers
- contact lists
- saved files (images, PDFs, Office documents)
At the same time, it activates continuous monitoring mechanisms. Content observers are created that detect every new photo stored on the device, while automatic scans for new documents are performed every five minutes.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
In this way, data leakage continues throughout the infection, even without any action from the user.

Persistence and automatic restart mechanisms
GhostChat incorporates persistence techniques that ensure a long-term presence on the device. During installation, it requests permissions that seem reasonable for a chat application, but in practice allow extensive surveillance.
It leverages Android's BOOT_COMPLETED broadcast intent to automatically activate on every device reboot. It also uses foreground services to stay active, bypassing the operating system's power-saving mechanisms.
See also: IPIDEA: Google “hit” one of the largest Residential Proxy Networks
Encrypted communication with servers
Communication with the command and control infrastructure is done over HTTPS, making malicious traffic almost invisible to simple network analysis. It is through this connection that stolen data is sent and new operating instructions are received.
GhostChat's architecture allows for both immediate mass information extraction and continuous monitoring over time, creating a comprehensive digital espionage framework.
What does this new threat indicate?
This particular campaign highlights a dangerous trend: attacks on mobile devices are no longer based solely on technical vulnerabilities, but on the emotional manipulation of users.

The combination of fake acquaintances, social engineering, and advanced spyware makes such attacks highly effective — and extremely difficult to detect.
For Android users, the basic defense remains avoiding unofficial APKs, carefully checking permissions , and being suspicious of apps that promise "free" or "exclusive" access.
In an era where the mobile phone is an extension of personal life, such threats remind us that digital security begins with the user's own awareness and critical thinking.
