Maikspy – A Spyware Attack on Windows & Android Users via Adult Games

A newly discovered dangerous Maikspy spyware distributing through adult games that specifically target Windows and Android Users to steal sensitive private data.

Initially, Maikspy spyware posed as U.S based adult film actress and trick users to click and download it to perform further malicious activities.

Attackers distributing the Maikspy spyware via malicious websites, after the complete infection it connect via command & control server and shares the stolen information.

Various Twitter handles has promoted the malicious adult games called Virtual Girlfriend and share the link to vicitms via short links and targeting windows and android Platform users.

Maikspy Spyware Attack on Android

Maikspy variant that distributed via various twitter accounts that posed as Virtual Girlfriend is created to run on Android by tricking vicitms to visit the malicious domain.

The domain name has been shortened and shared via Twitter and once the user visits the concerned link which leads the user to land the malicious website.

The reached website asked victims to choose the gender and select the first girlfriend which leads to download malicious APK that will be installed and launched.

Once it launched, it used a trick that shows “Error: 401. App not compatible. Uninstalling…” a fake attempt to uninstall the app due to compatible issue and the app is going to remove from the device.

This is an attempt to the user into thinking that the app is already removed from the device but it silently Spying in the background of the infected Android device.

Later it checks the permissions and Steal the user’s data such as phone number, Steal accounts, installed app list, contacts, SMS and send to the attacker via command and control sever.

Maikspy Spyware Attack on Windows

The Windows-based variant of the Mikespy distributed via same Twitter handles which insists used to visit the malicious website (hxxp://miakhalifagame[.]com/) and trick users to download a file called MiaKhalifa.rar .

Downloaded files contain a README.txt file with information for users to turn off the anti-virus software and how to turn on the network, which the attacker needs to steal and upload data to its C&C server.

According to Trend Micro Research, Another File called Uninstall.exe is a copy of the open-source hacking tool Mimikatz (https://github[.]com/gentilkiwi/mimikatz). It has the ability to extract plaintext passwords, hash, PIN code, and Kerberos tickets from memory.
Here, Uninstall.exe is used to get the Windows account and password, and then writes the result to C:\Users\%username%\AppData\local\password.txt.

Another file called Setup.exe  in the RAR will be performing a core stealing operation same as Andoird based Maikspy variant, it uploads all the stolen data into C&C server which is controlled by an attacker.

Same a Virtual Girlfriend malicious app, Maikspy using adult apps to reach victims and steal the sensitive information.

Balaji

BALAJI is an Ex-Security Researcher (Threat Research Labs) at Comodo Cybersecurity. Editor-in-Chief & Co-Founder - Cyber Security News & GBHackers On Security.

Recent Posts

Norway Recommends Replacing SSLVPN/WebVPN to Stop Cyber Attacks

A very important message from the Norwegian National Cyber Security Centre (NCSC) says that Secure Socket Layer/Transport Layer Security (SSL/TLS)…

1 day ago

New Linux Backdoor Attacking Linux Users Via Installation Packages

Linux is widely used in numerous servers, cloud infrastructure, and Internet of Things devices, which makes it an attractive target…

1 day ago

ViperSoftX Malware Uses Deep Learning Model To Execute Commands

ViperSoftX malware, known for stealing cryptocurrency information, now leverages Tesseract, an open-source OCR engine, to target infected systems, which extracts…

1 day ago

Santander Data Breach: Hackers Accessed Company Database

Santander has confirmed that there was a major data breach that affected its workers and customers in Spain, Uruguay, and…

1 day ago

U.S. Govt Announces Rewards up to $5 Million for North Korean IT Workers

The U.S. government has offered a prize of up to $5 million for information that leads to the arrest and…

1 day ago

Russian APT Hackers Attacking Critical Infrastructure

Russia leverages a mix of state-backed Advanced Persistent Threat (APT) groups and financially motivated cybercriminals to achieve its strategic goals,…

1 day ago