Maikspy – A Spyware Attack on Windows & Android Users via Adult Games

A newly discovered dangerous Maikspy spyware distributing through adult games that specifically target Windows and Android Users to steal sensitive private data.

Initially, Maikspy spyware posed as U.S based adult film actress and trick users to click and download it to perform further malicious activities.

Attackers distributing the Maikspy spyware via malicious websites, after the complete infection it connect via command & control server and shares the stolen information.

Various Twitter handles has promoted the malicious adult games called Virtual Girlfriend and share the link to vicitms via short links and targeting windows and android Platform users.

Maikspy Spyware Attack on Android

Maikspy variant that distributed via various twitter accounts that posed as Virtual Girlfriend is created to run on Android by tricking vicitms to visit the malicious domain.

The domain name has been shortened and shared via Twitter and once the user visits the concerned link which leads the user to land the malicious website.

The reached website asked victims to choose the gender and select the first girlfriend which leads to download malicious APK that will be installed and launched.

Once it launched, it used a trick that shows “Error: 401. App not compatible. Uninstalling…” a fake attempt to uninstall the app due to compatible issue and the app is going to remove from the device.

This is an attempt to the user into thinking that the app is already removed from the device but it silently Spying in the background of the infected Android device.

Later it checks the permissions and Steal the user’s data such as phone number, Steal accounts, installed app list, contacts, SMS and send to the attacker via command and control sever.

Maikspy Spyware Attack on Windows

The Windows-based variant of the Mikespy distributed via same Twitter handles which insists used to visit the malicious website (hxxp://miakhalifagame[.]com/) and trick users to download a file called MiaKhalifa.rar .

Downloaded files contain a README.txt file with information for users to turn off the anti-virus software and how to turn on the network, which the attacker needs to steal and upload data to its C&C server.

According to Trend Micro Research, Another File called Uninstall.exe is a copy of the open-source hacking tool Mimikatz (https://github[.]com/gentilkiwi/mimikatz). It has the ability to extract plaintext passwords, hash, PIN code, and Kerberos tickets from memory.
Here, Uninstall.exe is used to get the Windows account and password, and then writes the result to C:\Users\%username%\AppData\local\password.txt.

Another file called Setup.exe  in the RAR will be performing a core stealing operation same as Andoird based Maikspy variant, it uploads all the stolen data into C&C server which is controlled by an attacker.

Same a Virtual Girlfriend malicious app, Maikspy using adult apps to reach victims and steal the sensitive information.

Balaji

BALAJI is an Ex-Security Researcher (Threat Research Labs) at Comodo Cybersecurity. Editor-in-Chief & Co-Founder - Cyber Security News & GBHackers On Security.

Recent Posts

IT and security Leaders Feel Ill-Equipped to Handle Emerging Threats: New Survey

A comprehensive survey conducted by Keeper Security, in partnership with TrendCandy Research, has shed light on the growing concerns within…

3 hours ago

How to Analyse .NET Malware? – Reverse Engineering Snake Keylogger

Utilizing sandbox analysis for behavioral, network, and process examination provides a foundation for reverse engineering .NET malware.  The write-up outlines…

5 hours ago

GoPlus’s Latest Report Highlights How Blockchain Communities Are Leveraging Critical API Security Data To Mitigate Web3 Threats

GoPlus Labs, the leading Web3 security infrastructure provider, has unveiled a groundbreaking report highlighting the growing, widespread use and potential…

18 hours ago

C2A Security’s EVSec Risk Management and Automation Platform Gains Automotive Industry Favor as Companies Pursue Regulatory Compliance

In 2023, C2A Security added multiple OEMs and Tier 1s to its portfolio of customers, successful evaluations, and partnerships such…

19 hours ago

Wireshark 4.2.4 Released: What’s New!

Wireshark stands as the undisputed leader, offering unparalleled tools for troubleshooting, analysis, development, and education. The latest update, Wireshark 4.2.4,…

21 hours ago

Zoom Unveils AI-Powered All-In-One AI Work Workplace

Zoom has taken a monumental leap forward by introducing Zoom Workplace, an all-encompassing AI-powered platform designed to redefine how we…

22 hours ago