Malware

Hermit Android spyware used in Kazakhstan, Syria and Italy

0

A powerful enterprise-grade spyware dubbed Hermit has been used by entities operating from within Kazakhstan, Syria, and Italy over the years since 2019.

San Francisco-based cybersecurity firm Lookout attributed the spy software, which is equipped to target both Android and iOS, to an Italian company named RCS Lab S.p.A and Tykelab Srl, a telecom services provider which it suspects to be a front company. The researchers detected the campaign aimed at Kazakhstan in April 2022.

According to Lookout researchers Justin Albrecht and Paul Shunk, Hermit is modular and comes with numerous capabilities that allow it to exploit a rooted device, record audio and make and redirect phone calls, as well as collect data such as call logs, contacts, photos, device location and SMS messages.

The spyware is believed to be distributed via SMS messages that trick users into installing seemingly harmless apps from Samsung, Vivo, and Oppo, which, when opened, loads a website from the impersonated company while stealthily activating the kill chain in the background.

Hermit can abuse its access to accessibility services and other core components of the operating system (i.e., contacts, camera, calendar, clipboard, etc.) for most of its malicious activities.

RCS Lab, a known developer that has been active for over three decades, operates in the same market as Pegasus developer NSO Group Technologies and Gamma Group, which created FinFisher.

The companies claim to only sell to customers with legitimate use for surveillanceware, such as intelligence and law enforcement agencies. However, such tools have often been abused under the guise of national security to spy on business executives, human rights activists, journalists, academics and government officials.

Image Credits : Cybernews

Priyanka R
Cyber Security Enthusiast, Security Blogger, Technical Editor, Author at Cyber Safe News

WordPress sites force-updated to patch a critical plugin flaw

Previous article

Russian RSocks botnet disrupted by US

Next article

You may also like

More in Malware

Comments

Leave a reply

Your email address will not be published. Required fields are marked *