CYFIRMA Research

CYFIRMA Research- Unidentified Threat Actor Utilizes Android Malware to Target High-Value Assets in South Asia


Listen Later

Our team at CYFIRMA analyzed a malicious Android sample used in a targeted attack leveraging the Spynote Remote Administration Tool (RAT). We believe that the threat actor behind the targeted attack could be an APT. Delivered via WhatsApp with payloads disguised as apps like "Best Friend" and "Friend," the attack aimed to compromise high-value assets. All payloads were linked to the same command-and-control server and featured obfuscation techniques. While specific target details remain confidential, this case underscores the evolving tactics of threat actors. 

Link to the Research Report: Unidentified Threat Actor Utilizes Android Malware to Target High-Value Assets in South Asia - CYFIRMA

#CyberSecurity #MobileThreats #MalwareAnalysis #APT #spynote #androidmalware #craxrat   #spymax #mobilesecurity

https://www.cyfirma.com/

...more
View all episodesView all episodes
Download on the App Store

CYFIRMA ResearchBy CYFIRMA