An active Android malware campaign dubbed eXotic Visit was found targeting users in South Asia, particularly those in India and Pakistan, with malware distributed via dedicated websites and Google Play Store.
According to the Slovak cybersecurity firm, the activity which has been ongoing since November 2021, is not linked to any known threat group. It’s tracking the group behind the operation under the name Virtual Invaders.
ESET security researcher Lukáš Štefanko stated that the downloaded apps provide legitimate functionality, but also include code from the open-source Android XploitSPY RAT.
The campaign is highly targeted in nature, and the apps are available on Google Play having negligible number of installs ranging from zero to 45. The apps have since been taken down.
The fake-but-functional apps are disguised as messaging services like Alpha Chat, ChitChat, Defcom, Dink Messenger, Signal Lite, TalkU, WeTalk, Wicker Messenger, and Zaangi Chat. Approximately 380 victims are said to have downloaded the apps and created accounts to use them for messaging purposes.
Apps such as Sim Info and Telco DB, both of which claim to provide details about SIM owners simply by entering a Pakistan-based phone number are also a part of eXotic Visit. Other applications include a food ordering service in Pakistan as well as a legitimate Indian hospital called Specialist Hospital (now rebranded as Trilife Hospital).
XploitSPY, uploaded to GitHub as early as April 2020 by a user named RaoMK, is associated with an Indian cyber security solutions company called XploitWizer. It has also been described as a fork of another open-source Android trojan called L3MON, which, in turn, draws inspiration from AhMyth.
It comes with several features that allows it to gather sensitive data from infected devices, such as GPS locations, microphone recordings, contacts, SMS messages, call logs, and clipboard content; extract notification details from apps like WhatsApp, Facebook, Instagram, and Gmail; download and upload files; view installed apps; and queue commands.
Besides the malicious apps are also designed to take pictures and enumerate files in several directories related to screenshots, WhatApp, WhatsApp Business, Telegram, and an unofficial WhatsApp mod known as GBWhatsApp.
Throughout the years, the threat actors have customized their malicious code by adding obfuscation, emulator detection, hiding of [command-and-control] addresses, and use of a native library.
Štefanko concluded that the purpose of the campaign is espionage and is mainly targeting victims in Pakistan and India.

















Comments