Hackers working for the Main Directorate of the General Staff of the Armed Forces of the Russian Federation, known as the GRU, have been targeting Android devices in Ukraine with a new malicious framework named ‘Infamous Chisel.
The details of the mobile malware strain were disclosed by cybersecurity and intelligence agencies from Australia, Canada, New Zealand, the U.K., and the U.S.
The malicious software, dubbed Infamous Chisel and attributed to a Russian state-sponsored actor called Sandworm, has capabilities to enable unauthorized access to compromised devices, scan files, monitor traffic, and periodically steal sensitive information.
Sandworm, also known by the names FROZENBARENTS, Iron Viking, Seashell Blizzard, and Voodoo Bear, refers to the Russian Main Intelligence Directorate’s (GRU) Main Centre for Special Technologies (GTsST).
The hacking group which has been active since at least 2014, is best known for its string of disruptive and destructive cyber campaigns using malware such as Industroyer, BlackEnergy, and NotPetya.
Infamous Chisel is described as a collection of multiple components which is designed with the intent to enable remote access and exfiltrate information from Android phones.
The functions of the malware include scanning the devices for information and files matching a predefined set of file extensions, and also periodically scan the local network and offer SSH access.
Infamous Chisel also provides remote access by configuring and executing TOR with a hidden service which forwards to a modified Dropbear binary providing a SSH connection.
The Infamous Chisel components are low to medium sophistication and appear to have been developed with little regard to defense evasion or concealment of malicious activity.














Comments