Researchers at K7 Labs have uncovered a highly targeted Android spyware campaign aimed at Indian mobile users, using a seemingly innocent βWedding Invitationβ APK file shared via WhatsApp. Behind the social engineering lies a dangerous Remote Administration Tool (RAT)βSpyMaxβcapable of granting attackers full control over a victimβs device, including stealing SMS, OTPs, contacts, and banking credentials.
The malware begins its attack with a simple WhatsApp message disguised as a wedding invite. The file, βWedding Invitation.apkβ, is not from the Play Store, but from a contactβmaking the phishing vector appear legitimate.
Once opened, the app requests the user to:
- Set it as the default Home app
- Enable βInstall unknown appsβ permission
- Accept what appears to be a fake system update screen
βThe malware decrypts an app from the appβs assets folder and installs another app; the installed app package name is com.android.pictach,β the report explains.
The true payload, com.android.pictach, launches a sophisticated surveillance operation:
- Prompts full device control through fake system settings
- Logs all keystrokes, saving them to log-yyyy-mm-dd.log under Config/sys/apps/log
- Intercepts notifications (including bank OTPs and WhatsApp messages) via AccessibilityEvents
- Compresses exfiltrated data using gZIPOutputStream before sending to the attacker
βThis RAT intercepts Notification objects from AccessibilityEvents, extracting sensitive information such as bank OTPs, WhatsApp messages, and 2FA codes,β the report warns.
The malware connects to the Command-and-Control (C2) server at: 104.234.167[.]145:7860. Once a TCP connection is established, compressed data from the victim is transmitted.
Interestingly, K7 Labs found that the malware also checks for the presence of mobile security products, hinting at its intent to disable or evade detection.
βThis command collects the clipboard and SMS data and verifies the victimβs device for the presence of a hardcoded list of mobile security products.β
While the sample analyzed did not exhibit self-spreading behavior, researchers warn that the collection of the deviceβs contact list makes it possible for the malware to auto-forward itself in future versions.
βAs it collects the Contacts information, it is possible to forward the apk to the contacts list, though we didnβtΒ spot any such code in the sample we analyzed.β
Related Posts:
- Urgent Alert: “Free Wedding Invite” Scam Targets Senior Citizens, Steals Sensitive Data
- SpyMax β A New Android RAT Targeting Telegram Users
- Massive Android SMS Stealer Campaign Uncovered: Over 100,000 Malicious Apps Targeting Global Users
- CVE-2023-28936 allows attacker to access any arbitrary recording or room in Apache OpenMeetings
- APT29 Targets European Diplomats with Wine-Themed Phishing
Support Our Threat Intelligence
If you find our CVE report and cybersecurity news helpful, consider supporting our work.