• Menu
  • Skip to main content
  • Skip to primary sidebar

The Cyber Security News

Latest Cyber Security News

Header Right

  • Latest News
  • Vulnerabilities
  • Cloud Services
chinese eaglemsgspy spyware found exploiting mobile devices since 2017

Chinese EagleMsgSpy Spyware Found Exploiting Mobile Devices Since 2017

You are here: Home / General Cyber Security News / Chinese EagleMsgSpy Spyware Found Exploiting Mobile Devices Since 2017
December 11, 2024

Cybersecurity researchers have discovered a novel surveillance program that’s suspected to be used by Chinese police departments as a lawful intercept tool to gather a wide range of information from mobile devices.

The Android tool, codenamed EagleMsgSpy by Lookout, has been operational since at least 2017, with artifacts uploaded to the VirusTotal malware scanning platform as recently as September 25, 2024.

“The surveillanceware consists of two parts: an installer APK, and a surveillance client that runs headlessly on the device when installed,” Kristina Balaam, senior staff threat intelligence researcher at Lookout, said in a technical report shared with The Hacker News.

✔ Approved From Our Partners
AOMEI Backupper Lifetime

Protect and backup your data using AOMEI Backupper. AOMEI Backupper takes secure and encrypted backups from your Windows, hard drives or partitions. With AOMEI Backupper you will never be worried about loosing your data anymore.

Get AOMEI Backupper with 72% discount from an authorized distrinutor of AOMEI: SerialCart® (Limited Offer).

➤ Activate Your Coupon Code


“EagleMsgSpy collects extensive data from the user: third-party chat messages, screen recording and screenshot capture, audio recordings, call logs, device contacts, SMS messages, location data, network activity.”

EagleMsgSpy has been described by its developers as a “comprehensive mobile phone judicial monitoring product” that can obtain “real-time mobile phone information of suspects through network control without the suspect’s knowledge, monitor all mobile phone activities of criminals, and summarize them.”

Cybersecurity

The cybersecurity company attributed the surveillance program to a Chinese company called Wuhan Chinasoft Token Information Technology Co., Ltd. (aka Wuhan Zhongruan Tongzheng Information Technology Co., Ltd and Wuhan ZRTZ Information Technology Co, Ltd.), citing infrastructure overlap and references within the source code.

Lookout said the company’s internal documents it obtained from open directories on attacker-controlled infrastructure hint at the possibility of an iOS component, although such artifacts are yet to be uncovered in the wild.

What’s notable about EagleMsgSpy is the fact that it appears to require physical access to a target device in order to activate the information gathering operation by deploying an installer module that’s then responsible for delivering the core payload, otherwise referred to as MM or eagle_mm.

The surveillance client, for its part, can be acquired through various methods, such as QR codes or via a physical device that installs it on the phone when connected to USB. It’s believed that the actively maintained tool is used by multiple customers of the software vendor, given that it requires them to provide as input a “channel,” which corresponds to an account.

EagleMsgSpy’s Android version is designed to intercept incoming messages, collect data from QQ, Telegram, Viber, WhatsApp, and WeChat, initiate screen recording using the Media Projection API, and capture screenshots and audio recordings.

It’s also equipped to gather call logs, contact lists, GPS coordinates, details about network and Wi-Fi connections, files in external storage, bookmarks from the device browser, and a list of installed applications on the devices. The amassed data is subsequently compressed into password-protected archive files and exfiltrated to a command-and-control (C2) server.

Unlike early variants of EagleMsgSpy that employed few obfuscation techniques, the recent counterparts use an open-source application protection tool called ApkToolPlus to conceal classes. The surveillance module communicates with the C2 through WebSockets using the STOMP protocol to provide status updates and receive further instructions.

“EagleMsgSpy C2 servers host an administrative panel requiring user authentication,” Balaam said. “This administrative panel is implemented using the AngularJS framework, with appropriately configured routing and authentication preventing unauthorized access to the extensive admin API.”

It’s this panel source code that contains functions such as “getListIOS()” to distinguish between device platforms, alluding to the existence of an iOS version of the surveillance tool.

Lookout’s investigation has found that the panel allows customers, likely law enforcement agencies located in Mainland China, to trigger data collection in real-time from the infected devices. Another link that points to China is a hardcoded Wuhan-based phone number specified in several EagleMsgSpy samples.

Cybersecurity

The Hacker News also identified multiple patent applications filed by Wuhan ZRTZ Information Technology Co, Ltd. that delve into the various methods which can be used to “collect and analyze client data such as data of certain types like call record of the suspect’s mobile phone, short messages, an address book, instant chat software (QQ, WeChat, Momo, etc.) and so forth, and generate a relationship diagram between the suspect and others.”

Another patent details an “automatic evidence-collecting method and system,” indicating that the company behind EagleMsgSpy is primarily focused on developing products that have law enforcement use cases.

“It’s possible that the company incorporated the methodologies described in their patent applications – especially in cases in which they claim to have developed unique methods of creating relationship diagrams between victim datasets,” Balaam told The Hacker News. “However, we don’t have insight into how the company processed data server-side that was exfiltrated from victim devices.”

What’s more, Lookout said it identified two IP addresses tied to EagleMsgSpy C2 SSL certificates (202.107.80[.]34 and 119.36.193[.]210) that have been used by other China-linked surveillance tools such as PluginPhantom and CarbonSteal, both of which have been used to target Tibetan and Uyghur communities in the past.

“The malware is placed on victim devices and configured through access to the unlocked victim device,” the company said. “Once installed, the headless payload runs in the background, hiding its activities from the user of the device and collects extensive data from the user. Public CFPs for similar systems indicate that this surveillance tool or analogous systems are in use by many public security bureaus in China.”

Found this article interesting? Follow us on Twitter  and LinkedIn to read more exclusive content we post.


Some parts of this article are sourced from:
thehackernews.com

Previous Post: «researchers uncover espionage tactics of china based apt groups in southeast Researchers Uncover Espionage Tactics of China-Based APT Groups in Southeast Asia
Next Post: ZLoader Malware Returns With DNS Tunneling to Stealthily Mask C2 Comms zloader malware returns with dns tunneling to stealthily mask c2»

Reader Interactions

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Primary Sidebar

Report This Article

Recent Posts

  • Fortinet Releases Patch for Critical SQL Injection Flaw in FortiWeb (CVE-2025-25257)
  • PerfektBlue Bluetooth Vulnerabilities Expose Millions of Vehicles to Remote Code Execution
  • Securing Data in the AI Era
  • Critical Wing FTP Server Vulnerability (CVE-2025-47812) Actively Being Exploited in the Wild
  • Iranian-Backed Pay2Key Ransomware Resurfaces with 80% Profit Share for Cybercriminals
  • CISA Adds Citrix NetScaler CVE-2025-5777 to KEV Catalog as Active Exploits Target Enterprises
  • Critical mcp-remote Vulnerability Enables Remote Code Execution, Impacting 437,000+ Downloads
  • Fake Gaming and AI Firms Push Malware on Cryptocurrency Users via Telegram and Discord
  • Four Arrested in £440M Cyber Attack on Marks & Spencer, Co-op, and Harrods
  • What Security Leaders Need to Know About AI Governance for SaaS

Copyright © TheCyberSecurity.News, All Rights Reserved.