Android Spyware: GravityRAT steals WhatsApp backups

B2B Cyber ​​Security ShortNews

Share post

WhatsApp users should pay close attention to what they download on their Android smartphones. ESET researchers have detected a new Android version of GravityRAT spyware hiding in infected versions of BingeChat and Chatico messaging apps. Since SMEs in particular also like to use private smartphones including WhatsApp, caution is called for.

In the case under investigation, the malicious app steals WhatsApp backups and can also delete files on the devices. In order not to be immediately noticed, the app offers legitimate chat functionality based on the open-source application OMEMO Instant Messenger. ESET suspects the SpaceCobra group behind this campaign, which has probably been active since August 2022.

Used in targeted attacks

The malicious BingeChat app is distributed via a website that requires registration and is likely to be opened only when the attackers expect certain victims to visit it. "We found a web page that should provide the malicious app after tapping the DOWNLOAD APP button.

However, visitors must register for this. However, we had no login details and registration was closed. We assume that the operators provide registration only when they expect a specific victim to visit. Potential targets may need a specific IP address, geolocation, custom URL, or need to visit the website at a specific time,” says ESET researcher Lukas Stefanko. The app was never made available on the Google Play Store.

The rigged Chatico app targeted a user in India. Overall, the ESET researchers suspect that the campaign is very targeted and that carefully selected targets are being attacked.

Actors behind the campaign unclear

The group behind the malware remains unknown. Facebook researchers and Cisco Tales experts attribute GravityRAT to a Pakistan-based group. ESET monitors these under the name SpaceCobra and traces both the BingeChat and Chatico campaigns to this group.

As part of the legitimate functionality of the apps, they offer account creation and sign-up options. Before the user logs into the app, GravityRAT starts interacting with its C&C server, stealing the device user's data and waiting for commands to be executed. GravityRAT is able to search and exfiltrate call logs, contact lists, SMS messages, device location, basic device information and files with specific extensions for images, photos and documents. This version of GravityRAT has two small updates compared to previous publicly known versions of GravityRAT: exfiltration of WhatsApp backups and receiving commands to delete files.


B2B CYBER SECURITY asked chat GPT for GravityRAT

Here's what ChatGPT wants to know about GravityRAT.

ChatGPT to GravityRAT

GravityRAT is malicious software known as Remote Access Trojan (RAT). RATs are malware programs that allow an attacker to gain unauthorized access to the infected system and control it remotely. Here is some information about the GravityRAT group:

  • Origin: GravityRAT malware was first discovered in 2015 by a group known as "The Invincible". The group is believed to be from India as GravityRAT was primarily used against Indian targets.
  • objective: GravityRAT is designed to perform various malicious activities including spying on victims, gathering information, intercepting keystrokes, capturing screenshots and executing commands on the infected system. It is believed that the main targets of the GravityRAT group were governmental organizations, military establishments, diplomats and research institutions in India.
  • Functionality: GravityRAT malware typically proliferates using fake email attachments or through social engineering methods, in which attackers impersonate trusted organizations or individuals. Once a system is infected, the malware establishes a connection to a command and control server, which attackers can use to access and remotely control the infected system.
  • Activities: The GravityRAT group is known for running India-specific malware campaigns. It has developed different versions of the GravityRAT malware to make it harder to detect and streamline its malicious activities. The malware has evolved over time, introducing new features and techniques.

 

More at ESET.com

 


About ESET

ESET is a European company with headquarters in Bratislava (Slovakia). ESET has been developing award-winning security software since 1987 that has already helped over 100 million users enjoy secure technology. The broad portfolio of security products covers all common platforms and offers companies and consumers worldwide the perfect balance between performance and proactive protection. The company has a global sales network in over 180 countries and branches in Jena, San Diego, Singapore and Buenos Aires. For more information, visit www.eset.de or follow us on LinkedIn, Facebook and Twitter.


 

Matching articles on the topic

Report: 40 percent more phishing worldwide

The current spam and phishing report from Kaspersky for 2023 speaks for itself: users in Germany are after ➡ Read more

BSI sets minimum standards for web browsers

The BSI has revised the minimum standard for web browsers for administration and published version 3.0. You can remember that ➡ Read more

Data manipulation, the underestimated danger

Every year, World Backup Day on March 31st serves as a reminder of the importance of up-to-date and easily accessible backups ➡ Read more

Stealth malware targets European companies

Hackers are attacking many companies across Europe with stealth malware. ESET researchers have reported a dramatic increase in so-called AceCryptor attacks via ➡ Read more

IT security: Basis for LockBit 4.0 defused

Trend Micro, working with the UK's National Crime Agency (NCA), analyzed the unpublished version that was in development ➡ Read more

MDR and XDR via Google Workspace

Whether in a cafe, airport terminal or home office – employees work in many places. However, this development also brings challenges ➡ Read more

Windows operating systems: Almost two million computers at risk

There are no longer any updates for the Windows 7 and 8 operating systems. This means open security gaps and therefore worthwhile and ➡ Read more

Test: Security software for endpoints and individual PCs

The latest test results from the AV-TEST laboratory show very good performance of 16 established protection solutions for Windows ➡ Read more