Security News > 2023 > September > Transparent Tribe Uses Fake YouTube Android Apps to Spread CapraRAT Malware
The suspected Pakistan-linked threat actor known as Transparent Tribe is using malicious Android apps mimicking YouTube to distribute the CapraRAT mobile remote access trojan, demonstrating the continued evolution of the activity.
Transparent Tribe, also known as APT36, is known to target Indian entities for intelligence-gathering purposes, relying on an arsenal of tools capable of infiltrating Windows, Linux, and Android systems.
A crucial component of its toolset is CapraRAT, which has been propagated in the form of trojanized secure messaging and calling apps branded as MeetsApp and MeetUp.
These weaponized apps are distributed using social engineering lures.
The latest set of Android package files discovered by SentinelOne are engineered to masquerade as YouTube, one of which reaches out to a YouTube channel belonging to "Piya Sharma."
Once installed, the apps request intrusive permissions that allow the malware to harvest a wide range of sensitive data and exfiltrate it to an actor-controlled server.
News URL
https://thehackernews.com/2023/09/transparent-tribe-uses-fake-youtube.html
Related news
- SpyAgent Android malware steals your crypto recovery phrases from images (source)
- New Android SpyAgent Malware Uses OCR to Steal Crypto Wallet Recovery Keys (source)
- Beware: New Vo1d Malware Infects 1.3 Million Android-based TV Boxes Worldwide (source)
- New Android Malware 'Ajina.Banker' Steals Financial Data and Bypasses 2FA via Telegram (source)
- New Vo1d malware infects 1.3 million Android TV streaming boxes (source)
- New Vo1d malware infects 1.3 million Android streaming boxes (source)
- Android malware 'Necro' infects 11 million devices via Google Play (source)
- Necro malware continues to haunt side-loaders of dodgy Android mods (source)
- New Octo Android malware version impersonates NordVPN, Google Chrome (source)
- Necro Android Malware Found in Popular Camera and Browser Apps on Play Store (source)