Security News > 2023 > June > Android spyware camouflaged as VPN, chat apps on Google Play
Three Android apps on Google Play were used by state-sponsored threat actors to collect intelligence from targeted devices, such as location data and contact lists.
The malicious Android apps were discovered by Cyfirma, who attributed the operation with medium confidence to the Indian hacking group "DoNot," also tracked as APT-C-35, which has targeted high-profile organizations in Southeast Asia since at least 2018.
In 2021, an Amnesty International report linked the threat group to an Indian cybersecurity firm and highlighted a spyware distribution campaign that also relied on a fake chat app.
Both apps and a third from the same publisher, which does not appear malicious according to Cyfirma, remain available on Google Play.
Cyfirma's analysts have found that the code base of the hackers' VPN app was taken directly from the legitimate Liberty VPN product.
Direct messages on these apps direct victims to the Google Play store, a trusted platform that lends legitimacy to the attack, so they can be easily tricked into downloading suggested apps.
News URL
Related news
- Free VPN apps on Google Play turned Android phones into proxies (source)
- Apps secretly turning devices into proxy network nodes removed from Google Play (source)
- Google: Spyware vendors behind 50% of zero-days exploited in 2023 (source)
- Google Warns: Android Zero-Day Flaws in Pixel Phones Exploited by Forensic Companies (source)
- Google rolls out new Find My Device network to Android devices (source)
- 'eXotic Visit' Spyware Campaign Targets Android Users in India and Pakistan (source)
- Google One VPN axed for everyone but Pixel loyalists ... for now (source)