HomeSecurityGhostChat Spyware Targets Android Users

GhostChat Spyware Targets Android Users

A particularly disturbing Android spyware, dubbed GhostChat, highlights the growing convergence of social engineering and advanced surveillance techniques. The attack, which primarily targets users in Pakistan, relies on romance scams and fake dating appsto steal personal data and fully track mobile devices.

GhostChat Spyware

The GhostChat malware presents itself as a legitimate chat application, while in the background it operates as spyware , capable of collecting files, contacts, and user activity without any obvious signs.

The return of romance scams in a mobile environment

Romance scams are not a new phenomenon, but this campaign demonstrates that cybercriminals are adapting their techniques to modern mobile ecosystems. Instead of simple conversations on social networks, the deception is now delivered directly to the victim's device via malicious applications.

See also: ShinyHunters: New vishing campaign with hundreds of targets

This particular attack was detected in September 2025, when a suspicious Android app was uploaded to VirusTotal by a user in Pakistan, piqued the interest of cybersecurity researchers.

GhostChat: Disguise as a dating app

GhostChat appears as an app titled “Dating Apps without payment,” using the icon of a legitimate app available on Google Play. Despite this design, the malicious version was never hosted on an official app store.

Instead, victims are asked to install the APK file manually, enabling the option to install apps from unknown sources — a critical step that bypasses Google Play Protect during the initial infection stage.

A level of deception that stands out

Welivesecurity analysts point out that GhostChat stands out for its unusually elaborate deception mechanism. The app displays 14 female dating profiles , all locked, requiring a special password to unlock.

GhostChat Spyware Targets Android Users

These codes are embedded in the malicious code and distributed with the application, creating the illusion of limited or “exclusive” access. In this way, victims are convinced that they are participating in a private dating platform.

Redirect to WhatsApp and enhance reliability

After entering the correct code, the user is automatically redirected to WhatsApp and contacted by numbers controlled by the attackers. All numbers use Pakistani codes, which adds to the credibility of the scam locally.

While the victim believes they are chatting with real people, the spyware is already activated in the background.

See also: Microsoft 365: Outlook add-ins abused to steal email data

Full device monitoring

GhostChat immediately begins collecting critical information, such as:

  • unique device identifiers
  • contact lists
  • saved files (images, PDFs, Office documents)

At the same time, it activates continuous monitoring mechanisms. Content observers are created that detect every new photo stored on the device, while automatic scans for new documents are performed every five minutes.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

In this way, data leakage continues throughout the infection, even without any action from the user.

GhostChat Spyware Targets Android Users

Persistence and automatic restart mechanisms

GhostChat incorporates persistence techniques that ensure a long-term presence on the device. During installation, it requests permissions that seem reasonable for a chat application, but in practice allow extensive surveillance.

It leverages Android's BOOT_COMPLETED broadcast intent to automatically activate on every device reboot. It also uses foreground services to stay active, bypassing the operating system's power-saving mechanisms.

See also: IPIDEA: Google “hit” one of the largest Residential Proxy Networks

Encrypted communication with servers

Communication with the command and control infrastructure is done over HTTPS, making malicious traffic almost invisible to simple network analysis. It is through this connection that stolen data is sent and new operating instructions are received.

GhostChat's architecture allows for both immediate mass information extraction and continuous monitoring over time, creating a comprehensive digital espionage framework.

What does this new threat indicate?

This particular campaign highlights a dangerous trend: attacks on mobile devices are no longer based solely on technical vulnerabilities, but on the emotional manipulation of users.

GhostChat Spyware Targets Android Users

The combination of fake acquaintances, social engineering, and advanced spyware makes such attacks highly effective — and extremely difficult to detect.

For Android users, the basic defense remains avoiding unofficial APKs, carefully checking permissions , and being suspicious of apps that promise "free" or "exclusive" access.

In an era where the mobile phone is an extension of personal life, such threats remind us that digital security begins with the user's own awareness and critical thinking.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS