Security News > 2021 > March > Facebook Disrupts Chinese Spies Using iPhone, Android Malware
Facebook's threat intelligence team says it has disrupted a sophisticated Chinese spying team that routinely use iPhone and Android malware to hit journalists, dissidents and activists around the world.
The hacking group, known to malware hunters as Evil Eye, has used Facebook to plant links to watering hole websites rigged with exploits for the two major mobile platforms.
Facebook published details on the TTPs by the group, including precise, selective targeting of victims.
"This group took steps to conceal their activity and protect malicious tools by only infecting people with iOS malware when they passed certain technical checks, including IP address, operating system, browser and country and language settings," he explained.
The group has also used fake third party app stores and have been observed outsourcing Android malware development to two Chinese companies.
Facebook has published hashes and domains associated with this threat actor.
News URL
Related news
- Verizon outage: iPhones, Android devices stuck in SOS mode (source)
- TrickMo malware steals Android PINs using fake lock screen (source)
- What to do if your iPhone or Android smartphone gets stolen? (source)
- Russia targets Ukrainian conscripts with Windows, Android malware (source)
- Malvertising Campaign Hijacks Facebook Accounts to Spread SYS01stealer Malware (source)
- Android malware "FakeCall" now reroutes bank calls to attackers (source)
- New FakeCall Malware Variant Hijacks Android Devices for Fraudulent Banking Calls (source)
- New Android Banking Malware 'ToxicPanda' Targets Users with Fraudulent Money Transfers (source)
- Cyber crooks push Android malware via letter (source)
- NodeStealer Malware Targets Facebook Ad Accounts, Harvesting Credit Card Data (source)