The Android malware GravityRAT is back again, and this time this trojan disguised itself as a secure chat app with free encryption. The fake chat app is dubbed as SoSafe Chat, and this fake app is largely advertised on social media and other chatting platforms.
The primary goal of this fake encrypted chat application is to steal sensitive data from its compromised targets. While this particular RAT is mainly used and distributed by Pakistani actors, and they do so to target Indian users mainly.
Last year in 2020, this Trojan was distributed using an app known as Travel Mate Pro. And just like earlier, its motive didn’t change, as it still targeted the high-profiles like the officers of the Armed Forces in India.
GravityRAT is a particularly dangerous Android Trojan, and this type of RAT is used by threat actors to access the end device remotely.
Once the attacker installs it on a targeted device, the spyware can perform a wide range of malicious activities that enables threat actors to exfiltrate sensitive data, spy on the victim, and even track their location as well.
Here’s the metadata information of SoSafe Chat:-
The primary motto of this fake secure chat app, SoSafe Chat is to promote security and end-to-end encryption just like other players available in the market.
Right now, the website “sosafe[.]co[.]in” is still live, however, you won’t be able to browse the download link and the registration form, since they are not working anymore.
So, for now, the distribution methods and procedures remain anonymous, but, it has been noted that all the traffic of this website is derived through:-
Here are the features that are offered by this GravityRAT based malicious app:-
Here the security researchers at Cyble has recommended some mitigations:-
To avoid detection and find new ways to target users, the threat actors are constantly adapting new methods and sophisticated techniques.
Here, the reemergence of the GravityRAT malware with the ability to infect mobile devices and to confuse users into installing them disguised itself as a legitimate application clearly depicts that the operators of this malware are actively evolving it.
You can follow us on Linkedin, Twitter, Facebook for daily Cybersecurity, and hacking news updates.
A security researcher, exploring reverse engineering and exploit development, has successfully identified a critical vulnerability…
A security vulnerability has been identified in Brave Browser, potentially allowing malicious websites to masquerade…
A recent phishing campaign has targeted customers of SBI Bank through a deceptive message circulating…
The Gootloader malware family employs sophisticated social engineering tactics to infiltrate computers. By leveraging compromised…
A significant security vulnerability, designated CVE-2025-21613, has been discovered in the go-git library, used for…
Colm O hEigeartaigh announced a critical vulnerability affecting various versions of Apache CXF, a widely-used…