• Menu
  • Skip to main content
  • Skip to primary sidebar

The Cyber Security News

Latest Cyber Security News

Header Right

  • Latest News
  • Vulnerabilities
  • Cloud Services
Cyber Security News

Sextortionists Deploy New Spyware

You are here: Home / General Cyber Security News / Sextortionists Deploy New Spyware
December 16, 2020

New adware has been detected that targets iOS and Android buyers who patronize illicit websites that ordinarily offer escort solutions. 

The malware, named Goontact by the Lookout researchers who found out it, targets heterosexual people in China, Korea, Japan, Thailand, and Vietnam, thieving personal details from their mobile devices. 

✔ Approved Seller From Our Partners
Mullvad VPN Discount

Protect your privacy by Mullvad VPN. Mullvad VPN is one of the famous brands in the security and privacy world. With Mullvad VPN you will not even be asked for your email address. No log policy, no data from you will be saved. Get your license key now from the official distributor of Mullvad with discount: SerialCart® (Limited Offer).

➤ Get Mullvad VPN with 12% Discount


Researchers pointed out: “The forms of websites employed to distribute these malicious apps and the information and facts exfiltrated indicates that the top purpose is extortion or blackmail.”

Goontact usually disguises alone as secure messaging applications. The malware has been noticed exfiltrating a wide vary of facts, which include machine identifiers and phone number, contacts, SMS messages, location info, and pics on external storage.

Describing how buyers fall target to the spy ware, scientists wrote: “The scam commences when a prospective focus on is lured to a single of the hosted web pages the place they are invited to join with girls. 

“Account IDs for safe messaging apps such as KakaoTalk or Telegram are advertised on these web pages as the ideal types of conversation and the unique initiates a discussion. In truth, the targets are communicating with Goontact operators.”

By pretending that they are dealing with audio or video clip difficulties, the operators persuade their targets to put in or sideload a mobile software that has no serious consumer performance over and above stealing the victim’s handle ebook.

Scientists feel that the danger marketing campaign is staying operated by “a criminal offense affiliate” because websites related with the spyware are very similar in look, naming convention, and focused geographic area. 

The sites use logos affiliated with domains caught up in a former sextortion marketing campaign uncovered in 2015 by Development Micro. 

Goontact appears to be a the latest addition to a campaign that has been active since at minimum 2013. 

“The earliest sample of Goontact observed by Lookout was in November 2018, with matching APK packaging and signing dates, foremost us to imagine malware advancement probable began in this time body,” wrote scientists. 

The enterprise mobile provisioning profiles used by Goontact all reference apparently respectable organizations, together with Linkplay Tech Inc and Jinhua Changfeng Info Technology Co.

Researchers explained that it was unclear regardless of whether these signing identities have been compromised, or if they had been designed by malware operators spoofing representatives of the corporations.


Some pieces of this report are sourced from:
www.infosecurity-magazine.com

Previous Post: «Ryuk, Egregor Ransomware Attacks Leverage Systembc Backdoor Ryuk, Egregor Ransomware Attacks Leverage SystemBC Backdoor
Next Post: 45 million medical imaging files exposed online 45 Million Medical Imaging Files Exposed Online»

Reader Interactions

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Primary Sidebar

Report This Article

Recent Posts

  • Zero-Click Agentic Browser Attack Can Delete Entire Google Drive Using Crafted Emails
  • Critical XXE Bug CVE-2025-66516 (CVSS 10.0) Hits Apache Tika, Requires Urgent Patch
  • Chinese Hackers Have Started Exploiting the Newly Disclosed React2Shell Vulnerability
  • Intellexa Leaks Reveal Zero-Days and Ads-Based Vector for Predator Spyware Delivery
  • “Getting to Yes”: An Anti-Sales Guide for MSPs
  • CISA Reports PRC Hackers Using BRICKSTORM for Long-Term Access in U.S. Systems
  • JPCERT Confirms Active Command Injection Attacks on Array AG Gateways
  • Silver Fox Uses Fake Microsoft Teams Installer to Spread ValleyRAT Malware in China
  • ThreatsDay Bulletin: Wi-Fi Hack, npm Worm, DeFi Theft, Phishing Blasts— and 15 More Stories
  • 5 Threats That Reshaped Web Security This Year [2025]

Copyright © TheCyberSecurity.News, All Rights Reserved.