Transparent Tribe Extends Malware Campaign Against Android Users

01 Jul 2024

The threat actor known as Transparent Tribe has continued to unleash malware-laced Android apps as part of a social engineering campaign to target individuals of interest.

“These APKs continue the group’s trend of embedding spyware into curated video browsing applications, with a new expansion targeting mobile gamers, weapons enthusiasts, and TikTok fans,” SentinelOne security researcher Alex Delamotte said in a new report shared with The Hacker News.

The campaign, dubbed CapraTube, was first outlined by the cybersecurity company in September 2023, with the hacking crew employing weaponized Android apps impersonating legitimate apps like YouTube to deliver a spyware called CapraRAT, a modified version of AndroRAT with capabilities to capture a wide range of sensitive data.

Transparent Tribe, suspected to be of Pakistan origin, has leveraged CapraRAT for over two years in attacks targeting the Indian government and military personnel. The group has a history of leaning into spear-phishing and watering hole attacks to deliver a variety of Windows and Android spyware.

New Malicious APK Files Identified

  • Crazy Game (com.maeps.crygms.tktols)
  • Sexy Videos (com.nobra.crygms.tktols)
  • TikToks (com.maeps.vdosa.tktols)
  • Weapons (com.maeps.vdosa.tktols)

CapraRAT uses WebView to launch a URL to either YouTube or a mobile gaming site named CrazyGames[.]com, while, in the background, it abuses its permissions to access locations, SMS messages, contacts, and call logs; make phone calls; take screenshots; or record audio and video.

A notable change to the malware is that permissions such as READINSTALLSESSIONS, GETACCOUNTS, AUTHENTICATEACCOUNTS, and REQUESTINSTALLPACKAGES are no longer requested, suggesting that the threat actors are aiming to use it as a surveillance tool than a backdoor.

“The updates to the CapraRAT code between the September 2023 campaign and the current campaign are minimal, but suggest the developers are focused on making the tool more reliable and stable,” Delamotte said.

“The decision to move to newer versions of the Android OS are logical, and likely align with the group’s sustained targeting of individuals in the Indian government or military space, who are unlikely to use devices running older versions of Android, such as Lollipop which was released 8 years ago.”

Novel Android Banking Malware Snowblind Discovered

The disclosure comes as Promon disclosed a novel type of Android banking malware called Snowblind that, in ways similar to FjordPhantom, attempts to bypass detection methods and make use of the operating system’s accessibility services API in a surreptitious manner.

“Snowblind […] performs a normal repackaging attack but uses a lesser-known technique based on seccomp that is capable of bypassing many anti-tampering mechanisms,” the company said.

“Interestingly, FjordPhantom and Snowblind target apps from Southeast Asia and leverage powerful new attack techniques. That seems to indicate that malware authors in that region have become extremely sophisticated.”

Found this article interesting? Follow us on Twitter and LinkedIn to read more exclusive content we post.

Top charts for Mobile Android

uTorrent

uTorrent

Latest update uTorrent download for free for Windows PC or Android mobile

5
1032 reviews
6392820
downloads
Zona

Zona

Latest update Zona download for free for Windows PC or Android mobile

4
614 reviews
1273251
downloads
WinRAR

WinRAR

Latest update WinRAR download for free for Windows PC or Android mobile

5
735 reviews
495631
downloads
Minecraft

Minecraft

Latest update Minecraft download for free for Windows PC or Android mobile

5
750 reviews
453632
downloads

News and reviews for Mobile Android

Google Photos Tests AI 'Ask' Shortcut in the U.S.

Google Photos is trialing an AI 'Ask' feature shortcut in the U.S., enhancing user interaction by enabling direct photo queries.

Read more

Essential Android Phone Settings for Optimized Calling

Explore vital Android app settings to enhance call functionality and manage spam effectively. Insights for varied device menus.

Read more

Apple's App Store Now Accessible on Windows and Android

Apple has revamped its App Store web interface, allowing Windows and Android users to browse, increasing accessibility and easing navigation.

Read more

Game 'Green Light' Coming to PC, iOS, and Android by 2026

Dream Adventure Game 'Green Light' announced for PC, iOS, Android, 2026. Experience yanaginagi's world. Launch expected with English, Japanese support.

Read more

Free Apps Now Available for Android and iOS Users

Enjoy free premium apps on Android and iOS. Limited-time offer. Download now for lasting access.

Read more

AppHub Uninstalled from T-Mobile Devices for Improved Privacy

T-Mobile removes AppHub from Android devices amid privacy concerns over silent app installations.

Read more

LibriVox Makes Audiobooks Free for Android Auto Users

LibriVox offers over 18,000 free audiobooks for Android Auto users, enhancing long drives with public-domain classics and seamless in-car integration.

Read more

Unveil Huge Android App Discounts This Week

Discover significant app discounts on Android, including game and utility deals, available this week.

Read more

Latest Android Deals Include Trudograd Price Drop

Android deals now offer discounts on apps like Trudograd and Boxville 2, enhancing affordability for tech enthusiasts.

Read more

Top Free Apps to Enhance Your New Android Experience

Explore five free apps for Android that boost privacy, browsing, and productivity, offering solid performance with no cost.

Read more