Wednesday, January 22, 2025
HomeComputer SecurityMaikspy - A Spyware Attack on Windows & Android Users via Adult...

Maikspy – A Spyware Attack on Windows & Android Users via Adult Games

Published on

SIEM as a Service

Follow Us on Google News

A newly discovered dangerous Maikspy spyware distributing through adult games that specifically target Windows and Android Users to steal sensitive private data.

Initially, Maikspy spyware posed as U.S based adult film actress and trick users to click and download it to perform further malicious activities.

Attackers distributing the Maikspy spyware via malicious websites, after the complete infection it connect via command & control server and shares the stolen information.

Various Twitter handles has promoted the malicious adult games called Virtual Girlfriend and share the link to vicitms via short links and targeting windows and android Platform users.

Maikspy Spyware Attack on Android

Maikspy variant that distributed via various twitter accounts that posed as Virtual Girlfriend is created to run on Android by tricking vicitms to visit the malicious domain.

The domain name has been shortened and shared via Twitter and once the user visits the concerned link which leads the user to land the malicious website.

The reached website asked victims to choose the gender and select the first girlfriend which leads to download malicious APK that will be installed and launched.

Once it launched, it used a trick that shows “Error: 401. App not compatible. Uninstalling…” a fake attempt to uninstall the app due to compatible issue and the app is going to remove from the device.

This is an attempt to the user into thinking that the app is already removed from the device but it silently Spying in the background of the infected Android device.

Later it checks the permissions and Steal the user’s data such as phone number, Steal accounts, installed app list, contacts, SMS and send to the attacker via command and control sever.

Maikspy Spyware Attack on Windows

The Windows-based variant of the Mikespy distributed via same Twitter handles which insists used to visit the malicious website (hxxp://miakhalifagame[.]com/) and trick users to download a file called MiaKhalifa.rar .

Downloaded files contain a README.txt file with information for users to turn off the anti-virus software and how to turn on the network, which the attacker needs to steal and upload data to its C&C server.

According to Trend Micro Research, Another File called Uninstall.exe is a copy of the open-source hacking tool Mimikatz (https://github[.]com/gentilkiwi/mimikatz). It has the ability to extract plaintext passwords, hash, PIN code, and Kerberos tickets from memory.
Here, Uninstall.exe is used to get the Windows account and password, and then writes the result to C:\Users\%username%\AppData\local\password.txt.

Another file called Setup.exe  in the RAR will be performing a core stealing operation same as Andoird based Maikspy variant, it uploads all the stolen data into C&C server which is controlled by an attacker.

Same a Virtual Girlfriend malicious app, Maikspy using adult apps to reach victims and steal the sensitive information.

Balaji
Balaji
BALAJI is an Ex-Security Researcher (Threat Research Labs) at Comodo Cybersecurity. Editor-in-Chief & Co-Founder - Cyber Security News & GBHackers On Security.

Latest articles

PoC Exploit Released for TP-Link Code Execution Vulnerability(CVE-2024-54887)

A security researcher, exploring reverse engineering and exploit development, has successfully identified a critical...

Brave Browser Vulnerability Allows Malicious Website Appears as Trusted One

A security vulnerability has been identified in Brave Browser, potentially allowing malicious websites to...

Beware! Fake SBI Reward APK Attacking Users to Deliver Android Malware

A recent phishing campaign has targeted customers of SBI Bank through a deceptive message...

Gootloader Malware Employs Blackhat SEO Techniques To Attack Victims

The Gootloader malware family employs sophisticated social engineering tactics to infiltrate computers.By leveraging...

API Security Webinar

Free Webinar - DevSecOps Hacks

By embedding security into your CI/CD workflows, you can shift left, streamline your DevSecOps processes, and release secure applications faster—all while saving time and resources.

In this webinar, join Phani Deepak Akella ( VP of Marketing ) and Karthik Krishnamoorthy (CTO), Indusface as they explores best practices for integrating application security into your CI/CD workflows using tools like Jenkins and Jira.

Discussion points

Automate security scans as part of the CI/CD pipeline.
Get real-time, actionable insights into vulnerabilities.
Prioritize and track fixes directly in Jira, enhancing collaboration.
Reduce risks and costs by addressing vulnerabilities pre-production.

More like this

Is this Website Safe: How to Check Website Safety – 2025

is this website safe? In this digital world, Check a website is safe is...

WhatsApp Wins NSO in Pegasus Spyware Hacking Lawsuit After 5 Years

After a prolonged legal battle stretching over five years, WhatsApp has triumphed over NSO...

Firefox 133.0 Released with Multiple Security Updates – What’s New!

Mozilla has officially launched Firefox 133.0, offering enhanced features, significant performance improvements, and critical...