• Menu
  • Skip to main content
  • Skip to primary sidebar

The Cyber Security News

Latest Cyber Security News

Header Right

  • Latest News
  • Vulnerabilities
  • Cloud Services
bahamut cyber espionage hackers targeting android users with fake vpn

Bahamut Cyber Espionage Hackers Targeting Android Users with Fake VPN Apps

You are here: Home / General Cyber Security News / Bahamut Cyber Espionage Hackers Targeting Android Users with Fake VPN Apps
November 24, 2022

The cyber espionage group recognised as Bahamut has been attributed as behind a highly qualified marketing campaign that infects users of Android devices with destructive applications intended to extract sensitive info.

The action, which has been lively considering that January 2022, entails distributing rogue VPN applications by means of a bogus SecureVPN web page established up for this function, Slovak cybersecurity company ESET stated in a new report shared with The Hacker Information.

At least 8 unique variants of the adware apps have been found out to day, with them becoming trojanized versions of respectable VPN applications like SoftVPN and OpenVPN.

✔ Approved Seller From Our Partners
Mullvad VPN Discount

Protect your privacy by Mullvad VPN. Mullvad VPN is one of the famous brands in the security and privacy world. With Mullvad VPN you will not even be asked for your email address. No log policy, no data from you will be saved. Get your license key now from the official distributor of Mullvad with discount: SerialCart® (Limited Offer).

➤ Get Mullvad VPN with 12% Discount


The tampered apps and their updates are pushed to people as a result of the fraudulent web-site. It is really also suspected that the targets are diligently picked, since launching the app necessitates the victim to enter an activation key to permit the features.

This indicates the use of an undetermined distribution vector, while previous proof displays that it could choose the sort of spear-phishing e-mails, SMS messages, or direct messages on social media apps.

The activation key system is also made to talk with an actor-managed server, effectively avoiding the malware from staying unintentionally triggered right immediately after start on a non-qualified user unit.

Fake VPN Apps

Bahamut was unmasked in 2017 by Bellingcat as a hack-for-employ the service of operation concentrating on authorities officers, human legal rights groups, and other superior-profile entities in South Asia and the Center East with malicious Android and iOS apps to spy on its victims.

“Most likely the most unique component of Bahamut’s tradecraft that BlackBerry uncovered is the group’s use of initial, painstakingly crafted sites, programs and personas,” BlackBerry noted in October 2020.

Before this calendar year, Cyble comprehensive two sets of phishing attacks orchestrated by the group to force counterfeit Android apps masquerading as chat apps.

The hottest wave follows a similar trajectory, tricking customers into setting up seemingly innocuous VPN applications that can exfiltrate a vast swathe of details, like data files, contact lists, SMSes, phone call recordings, areas, and messages from WhatsApp, Fb Messenger, Signal, Viber, Telegram, and WeChat.

“The details exfiltration is performed by means of the keylogging functionality of the malware, which misuses accessibility products and services,” ESET researcher Lukáš Štefanko explained.

In a indicator that the marketing campaign is perfectly maintained, the threat actor at first packaged the destructive code within the SoftVPN software, ahead of shifting to OpenVPN, a shift described by the point that the true SoftVPN app stopped functioning and it was no for a longer period probable to create a VPN connection.

“The cellular campaign operated by the Bahamut APT team is still energetic it works by using the identical process of distributing its Android spy ware applications by using internet websites that impersonate or masquerade as reputable solutions, as has been found in the previous,” Štefanko added.

Found this write-up appealing? Abide by THN on Fb, Twitter  and LinkedIn to read a lot more special content material we publish.


Some areas of this post are sourced from:
thehackernews.com

Previous Post: «Cyber Security News UK Cops Lead Action Against Fraud Site that Made £100m+
Next Post: Boost Your Security with Europe’s Leading Bug Bounty Platform boost your security with europe's leading bug bounty platform»

Reader Interactions

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Primary Sidebar

Report This Article

Recent Posts

  • Zero-Click Agentic Browser Attack Can Delete Entire Google Drive Using Crafted Emails
  • Critical XXE Bug CVE-2025-66516 (CVSS 10.0) Hits Apache Tika, Requires Urgent Patch
  • Chinese Hackers Have Started Exploiting the Newly Disclosed React2Shell Vulnerability
  • Intellexa Leaks Reveal Zero-Days and Ads-Based Vector for Predator Spyware Delivery
  • “Getting to Yes”: An Anti-Sales Guide for MSPs
  • CISA Reports PRC Hackers Using BRICKSTORM for Long-Term Access in U.S. Systems
  • JPCERT Confirms Active Command Injection Attacks on Array AG Gateways
  • Silver Fox Uses Fake Microsoft Teams Installer to Spread ValleyRAT Malware in China
  • ThreatsDay Bulletin: Wi-Fi Hack, npm Worm, DeFi Theft, Phishing Blasts— and 15 More Stories
  • 5 Threats That Reshaped Web Security This Year [2025]

Copyright © TheCyberSecurity.News, All Rights Reserved.