Monday, April 28, 2025
HomeMalwareGravity Malware Returns As Fake Encrypted Chat App To Steal Sensitive Data

Gravity Malware Returns As Fake Encrypted Chat App To Steal Sensitive Data

Published on

SIEM as a Service

Follow Us on Google News

The Android malware GravityRAT is back again, and this time this trojan disguised itself as a secure chat app with free encryption. The fake chat app is dubbed as SoSafe Chat, and this fake app is largely advertised on social media and other chatting platforms.

The primary goal of this fake encrypted chat application is to steal sensitive data from its compromised targets. While this particular RAT is mainly used and distributed by Pakistani actors, and they do so to target Indian users mainly.

Last year in 2020, this Trojan was distributed using an app known as Travel Mate Pro. And just like earlier, its motive didn’t change, as it still targeted the high-profiles like the officers of the Armed Forces in India.

- Advertisement - Google News

Fake Secure Chat App

GravityRAT is a particularly dangerous Android Trojan, and this type of RAT is used by threat actors to access the end device remotely.

Once the attacker installs it on a targeted device, the spyware can perform a wide range of malicious activities that enables threat actors to exfiltrate sensitive data, spy on the victim, and even track their location as well.

Here’s the metadata information of SoSafe Chat:-

  • App Name: SoSafe Chat
  • Package Name: eu.siacs.conversations
  • SHA256 Hash: c7d01eacfb80cea5fcfd643cddec8bdc4ed9fde8d1161e4958cc71f9e82c6469

The primary motto of this fake secure chat app, SoSafe Chat is to promote security and end-to-end encryption just like other players available in the market.

Right now, the website “sosafe[.]co[.]in” is still live, however, you won’t be able to browse the download link and the registration form, since they are not working anymore. 

So, for now, the distribution methods and procedures remain anonymous, but, it has been noted that all the traffic of this website is derived through:-

  • Malvertising
  • Social media platforms
  • Instant messaging platforms

Spying Abilities

Here are the features that are offered by this GravityRAT based malicious app:-

  • Read SMS, Call Logs, and Contacts data
  • Change or modify system settings
  • Read current cellular network information, the phone number and the serial number of the victim’s phone, the status of any ongoing calls, and a list of any Phone Accounts registered on the device
  • Read or write the files on the device’s external storage
  • Record audio
  • Gets connected network information
  • Get the device’s location

Permissions Requested by SoSafe Chat

Recommendations

Here the security researchers at Cyble has recommended some mitigations:-

  • Only from the official app stores you should download and install apps.
  • Always use strong passwords, and change them frequently.
  • On your Android device always make sure the Google Play Protect is enabled.
  • While enabling any permissions on your device always beware.
  • Immediately delete if you find any suspicious applications on your device.
  • To monitor and block the malware infection, always use the shared IOCs.
  • Always keep your Antivirus software updated with the latest version.
  • Always keep the OS and apps updated with the latest version.
  • Enable two-factor authentication. 

To avoid detection and find new ways to target users, the threat actors are constantly adapting new methods and sophisticated techniques.

Here, the reemergence of the GravityRAT malware with the ability to infect mobile devices and to confuse users into installing them disguised itself as a legitimate application clearly depicts that the operators of this malware are actively evolving it.

You can follow us on LinkedinTwitterFacebook for daily Cybersecurity, and hacking news updates.

Balaji
Balaji
BALAJI is an Ex-Security Researcher (Threat Research Labs) at Comodo Cybersecurity. Editor-in-Chief & Co-Founder - Cyber Security News & GBHackers On Security.

Latest articles

How To Use Digital Forensics To Strengthen Your Organization’s Cybersecurity Posture

Digital forensics has become a cornerstone of modern cybersecurity strategies, moving beyond its traditional...

Building A Strong Compliance Framework: A CISO’s Guide To Meeting Regulatory Requirements

In the current digital landscape, Chief Information Security Officers (CISOs) are under mounting pressure...

Two Systemic Jailbreaks Uncovered, Exposing Widespread Vulnerabilities in Generative AI Models

Two significant security vulnerabilities in generative AI systems have been discovered, allowing attackers to...

New AI-Generated ‘TikDocs’ Exploits Trust in the Medical Profession to Drive Sales

AI-generated medical scams across TikTok and Instagram, where deepfake avatars pose as healthcare professionals...

Resilience at Scale

Why Application Security is Non-Negotiable

The resilience of your digital infrastructure directly impacts your ability to scale. And yet, application security remains a critical weak link for most organizations.

Application Security is no longer just a defensive play—it’s the cornerstone of cyber resilience and sustainable growth. In this webinar, Karthik Krishnamoorthy (CTO of Indusface) and Phani Deepak Akella (VP of Marketing – Indusface), will share how AI-powered application security can help organizations build resilience by

Discussion points


Protecting at internet scale using AI and behavioral-based DDoS & bot mitigation.
Autonomously discovering external assets and remediating vulnerabilities within 72 hours, enabling secure, confident scaling.
Ensuring 100% application availability through platforms architected for failure resilience.
Eliminating silos with real-time correlation between attack surface and active threats for rapid, accurate mitigation

More like this

North Korean APT Hackers Pose as Companies to Spread Malware to Job Seekers

Silent Push Threat Analysts have uncovered a chilling new cyberattack campaign orchestrated by the...

Russian VPS Servers With RDP and Proxy Servers Enable North Korean Cybercrime Operations

Trend Research has uncovered a sophisticated network of cybercrime operations linked to North Korea,...

New Malware Hijacks Docker Images Using Unique Obfuscation Technique

A recently uncovered malware campaign targeting Docker, one of the most frequently attacked services...