Thursday, February 27, 2025
HomeMalwareProject Spy - A Spyware Campaign That Hack Android & iOS Devices...

Project Spy – A Spyware Campaign That Hack Android & iOS Devices via Coronavirus Update App

Published on

SIEM as a Service

Follow Us on Google News

Researchers discovered a new cyberespionage campaign named Project Spy through which hackers targeting Android and iOS devices with spyware using Coronavirus Update App.

Cybercriminals taking advantage of the currently ongoing COVID-19 pandemic as a lure and lunching a fake Coronavirus updates App and install spyware on the victim’s devices.

We have reported several ongoing malware and phishing campaigns related to Coronavirus pandemic targeting billions of mobile users every day.

“Attackers who behind this malware are amateurs and the spyware contains incomplete iOS codes used in this campaign may have been bought while other capabilities appear to have been added.” Trend Micro researchers said.

Project Spy Activities and Capabilities

Researchers observed this mobile spyware campaign at the end of the March, and the Corna virus update app masquerading and tempt users to download and install it on their device.

The Project Spy has installed with various data-stealing capabilities that include capable of stealing messages from popular messaging apps by gaining permission from the users.

It also requests permission to access the storage and abusing notification permissions to read the notification content.

There are following data collection activities are observed:-

  • Upload GSM, WhatsApp, Telegram, Facebook, and Threema messages
  • Upload voice notes, contacts stored, accounts, call logs, location information, and images
  • Upload the expanded list of collected device information (e.g., IMEI, product, board, manufacturer, tag, host, Android version, application version, name, model brand, user, serial, hardware, bootloader, and device ID)
  • Upload SIM information (e.g., IMSI, operator code, country, MCC-mobile country, SIM serial, operator name, and mobile number)
  • Upload wifi information (e.g., SSID, wifi speed, and MAC address)
  • Upload other information (e.g., display, date, time, fingerprint, created at, and updated at)

Researchers also observed another 2 earlier versions of the Corona Virus Update app detected in May 2019.

The first version of Corona update app has limited capabilities of following:-

  • Collect device and system information (i.e., IMEI, device ID, manufacturer, model and phone number), location information, contacts stored, and call logs
  • Collect and send SMS
  • Take pictures via the camera
  • Upload recorded MP4 files
  • Monitor calls

In the second version appeared as Wabi Music, and copied a popular video-sharing social networking service as its backend login page.

This version also has a similar version of similar capabilities to the first version of the following;-

  • Stealing notification messages sent from WhatsApp, Facebook, and Telegram
  • Abandoning the FTP mode of uploading the recorded images

The developer’s name listed was “concipit1248” in Google Play, and the researchers check with the same code on the App store and found two other apps that targeted the app store.

According to Trend Micro research ” the “Concipit1248” app requested permissions to open the device camera and read photos, the code only can upload a self-contained PNG file to a remote server. This may imply the “Concipit1248” app is still incubating”.

Currently ongoing this Cyberespionage installed this Corona virus update spyware app on several country users devices including Pakistan, India, Afghanistan, Bangladesh, Iran, Saudi Arabia, Austria, Romania, Grenada, and Russia.

You can follow us on LinkedinTwitterFacebook for daily Cybersecurity and hacking news updates.

Indicators of Compromise

e394e53e53cd9047d6cff184ac333ef7698a34b777ae3aac82c2c669ef661dfe
e8d4713e43241ab09d40c2ae8814302f77de76650ccf3e7db83b3ac8ad41f9fa
29b0d86ae68d83f9578c3f36041df943195bc55a7f3f1d45a9c23f145d75af9d
3a15e7b8f4e35e006329811a6a2bf291d449884a120332f24c7e3ca58d0fbbd
Balaji
Balaji
BALAJI is an Ex-Security Researcher (Threat Research Labs) at Comodo Cybersecurity. Editor-in-Chief & Co-Founder - Cyber Security News & GBHackers On Security.

Latest articles

Cisco Nexus Vulnerability Allows Attackers to Inject Malicious Commands

Cisco Systems has issued a critical security advisory for a newly disclosed command injection...

New Wi-Fi Jamming Attack Can Disable Specific Devices

A newly discovered Wi-Fi jamming technique enables attackers to selectively disconnect individual devices from...

GitLab Vulnerabilities Allow Attackers to Bypass Security and Run Arbitrary Scripts

GitLab has urgently released security updates to address multiple high-severity vulnerabilities in its platform...

LibreOffice Flaws Allow Attackers to Run Malicious Files on Windows

A high-severity security vulnerability (CVE-2025-0514) in LibreOffice, the widely used open-source office suite, has...

Supply Chain Attack Prevention

Free Webinar - Supply Chain Attack Prevention

Recent attacks like Polyfill[.]io show how compromised third-party components become backdoors for hackers. PCI DSS 4.0’s Requirement 6.4.3 mandates stricter browser script controls, while Requirement 12.8 focuses on securing third-party providers.

Join Vivekanand Gopalan (VP of Products – Indusface) and Phani Deepak Akella (VP of Marketing – Indusface) as they break down these compliance requirements and share strategies to protect your applications from supply chain attacks.

Discussion points

Meeting PCI DSS 4.0 mandates.
Blocking malicious components and unauthorized JavaScript execution.
PIdentifying attack surfaces from third-party dependencies.
Preventing man-in-the-browser attacks with proactive monitoring.

More like this

Ghostwriter Malware Targets Government Organizations with Weaponized XLS File

A new wave of cyberattacks attributed to the Ghostwriter Advanced Persistent Threat (APT) group...

Threat Actors Using Ephemeral Port 60102 for Covert Malware Communications

Recent cybersecurity investigations have uncovered a sophisticated technique employed by threat actors to evade...

Poseidon Mac Malware Hiding Within PKG Files to Evade Detections

A recent discovery by cybersecurity researchers has revealed that the Poseidon malware, a macOS-targeting...