Hackers are using this Android malware to spy on Israeli soldiers

1487501597 cybersecurity4

cybersecurity4.jpg

Hackers are carrying out surveillance on members of the Israeli military by hacking into their Android phones in order to monitor activity and steal data – potentially including photos and audio recordings – according to security companies.

Developed and deployed by currently by a so-far unidentified group, ViperRAT is designed to collect sensitive information from infected devices, with those behind the malware seemingly most interested in images and audio files, althoughalso keen on SMS messages, contact books and access to the device location.

ADVERTISEMENT

Cybersecurity researchers at both Lookout and Kaspersky Lab have been monitoring the ViperRAT campaign, which is still in its early stages and still actively attempting to compromise Android devices.

Over 100 Israeli servicemen – using devices from Samsung, HTC, LG and Huawei – are thought to have been hit so far and almost 9,000 files stolen from compromised devices; but it’s likely the IDF isn’t the only target.

“It has been used directly against IDF personnel, however there’s also a good indication that it has been deployed in other campaigns against other groups,” Michael Flossman, security research services lead EMEA at Lookout, told ZDNet.

The attackers use social engineering in order to compromise the Android smartphones of IDF soldiers, with hackers posing as young women on social media in order to entice targets into exchanging messages using Facebook messenger.

Once the hacker builds up a rapport with the target, they suggest the installation of an additional application for easier communication, which they send for installation directly via a malicious URL. Attackers have also been seen spreading the malware using a dropper hidden in a billiards game, an Israeli love songs player, and another app.

It’s this dropper which contains the malware, which in order to be installed, requires the victim to allow various permissions which will enable the attackers to carry out surveillance using the device.

Disguised in the system as an update for WhatsApp, this payload allows the attackers to execute on demand commands – enabling them to to take photos and record audio at will – and to schedule tasks allowing for the collection of stolen data on a command and control server.

Using a Websocket protocall, ViperRAT can collect information about the device, browse the web, send and receive messages, eavesdrop on conversations and perhaps most importantly for the perpetrators – take photos at any time.

The actors behind the attack can also issue commands to search for and steal PDF and Office documents and any sensitive information which they might contain, actions with could further compromise targets.

While the malicious actors behind ViperRAT have yet to be explicitly identified, their activity patterns suggest that the cyberespionage is being carried out by a group operating out of the Middle East.

“They operate between Sunday and Thursday, so they have a work week that’s followed by several Middle Eastern countries,” says Flossman, who explains how there’s one simple way which users can avoid becoming a target of ViperRAT. “Ensuring you don’t download applications from untrusted sources would be a good recommendation”.

The IDF had not responded to a request for comment at the time of publication.

READ MORE ON CYBERESPIONAGE

(via PCMag)



Notice an issue?

Arabian Post strives to deliver the most accurate and reliable information to its readers. If you believe you have identified an error or inconsistency in this article, please don't hesitate to contact our editorial team at editor[at]thearabianpost[dot]com. We are committed to promptly addressing any concerns and ensuring the highest level of journalistic integrity.


ADVERTISEMENT
Social Media Auto Publish Powered By : XYZScripts.com
Just in:
Trashure Hunt Opens at Raffles City, Turning Singapore’s Waste Challenge Into Public Art // MuddyWater masks espionage behind ransomware playbook // J.P. Morgan pares Brent outlook on softer demand // ADNOC Drilling puts AI rig to work early // Pulsar International (“Pulsar”) announces agreement as an authorized reseller of Amazon Leo to bring high-speed satellite internet to commercial maritime customers // Biosphere Labs strengthens Abu Dhabi biotech hub // GTA 6 pre-orders fuel scam warnings // HKRITA Signs MoU with Jeanologia and Looptworks to Establish the Green Machine Circular Textile Ecosystem, Marking a Breakthrough in Scalable Textile Recycling // GEMS enrolment softens as war delays relocations // My Wallet broadens reach beyond TON // HKSTP Leads Largest-Ever Hong Kong Delegation to BIO 2026 Showcasing Life and Health Tech Strength // Impossible Marketing Unveils ImpossiblePlus™ AI SEO Solution for Singapore Businesses // UAE fines foreign bank branch over compliance lapses // Cornell robot electrifies weed control race // Cockroach Party channels youth anger into protest // Gaslight malware exposes AI triage blind spot // Dubai summit sets global sports agenda // SCG Showcases Green Innovations and Low-Carbon Cement at Cemtech Asia 2026, Reinforcing ASEAN Leadership and Commitment to the Net Zero Pathway // Mannings Continues “Safe Disposal of Unused Medicines Programme” for the Fourth Year Partnering with Community Organisations to Expand Network to 75 Collection Points // Brussels advances digital euro payment push //