Transparent Tribe Extends Malware Campaign Against Android Users

01 Jul 2024

The threat actor known as Transparent Tribe has continued to unleash malware-laced Android apps as part of a social engineering campaign to target individuals of interest.

“These APKs continue the group’s trend of embedding spyware into curated video browsing applications, with a new expansion targeting mobile gamers, weapons enthusiasts, and TikTok fans,” SentinelOne security researcher Alex Delamotte said in a new report shared with The Hacker News.

The campaign, dubbed CapraTube, was first outlined by the cybersecurity company in September 2023, with the hacking crew employing weaponized Android apps impersonating legitimate apps like YouTube to deliver a spyware called CapraRAT, a modified version of AndroRAT with capabilities to capture a wide range of sensitive data.

Transparent Tribe, suspected to be of Pakistan origin, has leveraged CapraRAT for over two years in attacks targeting the Indian government and military personnel. The group has a history of leaning into spear-phishing and watering hole attacks to deliver a variety of Windows and Android spyware.

New Malicious APK Files Identified

  • Crazy Game (com.maeps.crygms.tktols)
  • Sexy Videos (com.nobra.crygms.tktols)
  • TikToks (com.maeps.vdosa.tktols)
  • Weapons (com.maeps.vdosa.tktols)

CapraRAT uses WebView to launch a URL to either YouTube or a mobile gaming site named CrazyGames[.]com, while, in the background, it abuses its permissions to access locations, SMS messages, contacts, and call logs; make phone calls; take screenshots; or record audio and video.

A notable change to the malware is that permissions such as READINSTALLSESSIONS, GETACCOUNTS, AUTHENTICATEACCOUNTS, and REQUESTINSTALLPACKAGES are no longer requested, suggesting that the threat actors are aiming to use it as a surveillance tool than a backdoor.

“The updates to the CapraRAT code between the September 2023 campaign and the current campaign are minimal, but suggest the developers are focused on making the tool more reliable and stable,” Delamotte said.

“The decision to move to newer versions of the Android OS are logical, and likely align with the group’s sustained targeting of individuals in the Indian government or military space, who are unlikely to use devices running older versions of Android, such as Lollipop which was released 8 years ago.”

Novel Android Banking Malware Snowblind Discovered

The disclosure comes as Promon disclosed a novel type of Android banking malware called Snowblind that, in ways similar to FjordPhantom, attempts to bypass detection methods and make use of the operating system’s accessibility services API in a surreptitious manner.

“Snowblind […] performs a normal repackaging attack but uses a lesser-known technique based on seccomp that is capable of bypassing many anti-tampering mechanisms,” the company said.

“Interestingly, FjordPhantom and Snowblind target apps from Southeast Asia and leverage powerful new attack techniques. That seems to indicate that malware authors in that region have become extremely sophisticated.”

Found this article interesting? Follow us on Twitter and LinkedIn to read more exclusive content we post.

Top charts for Mobile Android

uTorrent

uTorrent

Latest update uTorrent download for free for Windows PC or Android mobile

5
1032 reviews
6787439
downloads
Zona

Zona

Latest update Zona download for free for Windows PC or Android mobile

4
614 reviews
1449853
downloads
WinRAR

WinRAR

Latest update WinRAR download for free for Windows PC or Android mobile

5
735 reviews
594657
downloads
Minecraft

Minecraft

Latest update Minecraft download for free for Windows PC or Android mobile

5
750 reviews
466199
downloads

News and reviews for Mobile Android

Upgrade Transforms NotebookLM Android with AI Enhancements

Google's NotebookLM for Android now features AI-powered multimedia handling, enhancing productivity with new mobile-centric tools.

Read more

Google Introduces Incognito Mode to Android App

Google app on Android now supports Incognito, enhancing privacy by encrypting searches and limiting data leaks.

Read more

Google App Adds Privacy Feature on Android

Google app for Android introduces 'Search History Off' toggle, enhancing user privacy. Expected rollout worldwide in coming months.

Read more

BuzzKill App Optimizes Android Notifications for Focus

BuzzKill, privacy-focused, adjusts Android notifications. Available now, it helps focus by reducing distractions.

Read more

Trackers in Android Apps Raise Privacy Concerns

Hidden trackers in Android apps spark privacy concerns. Apps like TrackerControl help identify and block these trackers, boosting defenses.

Read more

Epic Games Offers Darkside Detective for Free on Mobile

Darkside Detective now free on mobile through Epic Games until 2023-12-11, saving users $13.98.

Read more

Google Expands Autofill in Chrome for Seamless Form Filling

Google updates Chrome Autofill: now supports vehicle details in Google Wallet for easier form filling across devices.

Read more

Highlight Android Deals: Boxville Discounts Today

Today's Android deals cover Boxville 1, Boxville 2, Dungeon Defense, and more. Prices changing quickly.

Read more

DeckSettings App Enhances Steam Deck Game Compatibility Reference

DeckSettings improves Steam Deck game compatibility, offering critical playability info with Android availability and iOS beta on the horizon.

Read more

Russia Bans Key Messaging Apps

Russia bans WhatsApp, Snapchat, and FaceTime. Max, a domestic app, emerges as a replacement.

Read more