Security News > 2021 > March > Facebook Disrupts Chinese Spies Using iPhone, Android Malware

Facebook Disrupts Chinese Spies Using iPhone, Android Malware
2021-03-24 18:56

Facebook's threat intelligence team says it has disrupted a sophisticated Chinese spying team that routinely use iPhone and Android malware to hit journalists, dissidents and activists around the world.

The hacking group, known to malware hunters as Evil Eye, has used Facebook to plant links to watering hole websites rigged with exploits for the two major mobile platforms.

Facebook published details on the TTPs by the group, including precise, selective targeting of victims.

"This group took steps to conceal their activity and protect malicious tools by only infecting people with iOS malware when they passed certain technical checks, including IP address, operating system, browser and country and language settings," he explained.

The group has also used fake third party app stores and have been observed outsourcing Android malware development to two Chinese companies.

Facebook has published hashes and domains associated with this threat actor.


News URL

http://feedproxy.google.com/~r/Securityweek/~3/b6aPlTnPQME/facebook-disrupts-chinese-spies-using-iphone-android-malware

Related vendor

VENDOR LAST 12M #/PRODUCTS LOW MEDIUM HIGH CRITICAL TOTAL VULNS
Facebook 30 2 44 52 19 117
Android 4 0 17 2 0 19