Firewall Daily

Hackers Use Android Spyware ‘Dracarys’ In Cyber Espionage Activities

Researchers identified a malicious code disguised in the Signal messaging app by the Bitter APT group to target users with Android spyware called Dracarys. The new threat vector came to light when Facebook’s parent company released its Q2 2022 adversarial risk report on cyber espionage. Cyber-intelligence firm, Cyble reported a trojanized model of the Signal messaging app in a technical report detailing Dracarys. According to the Cyble Report, “The Bitter APT is actively involved in both desktop and mobile malware campaigns and uses techniques like spear phishing emails, exploiting known vulnerabilities to deliver Remote Access Trojan (RAT) and other malware families.” Attackers used legitimate-looking apps and app stores to target users in India, Pakistan, New Zealand, and the United Kingdom.

Using trojanized dropper apps, the miscreants sent Dracarys under the guise of available channels such as Signal, Telegram, YouTube, and WhatsApp. Dracarys accessed sensitive information, including files, call logs, SMS, contact, and GPS location. The malware comes with the capacity to steal data from the victim’s device with access to their microphone-activation capabilities.

The attacks surpassed detection and blocking as broken links and images with phishing links were sent on chat, making the users type the link on the browser, leading to a successful attack. Due to the permissions requested while downloading infected apps, the attackers could make calls and access the entire storage, including the camera of the victim’s device.

Furthermore, Dracarys can cause damage without the user’s knowledge by auto-granting permissions, clicking on the screen and functioning in the background even when the user is not using the app. Taking screenshots and transferring the same to the attackers is another harmful capability of the adware. The same pattern as noted by Cyble was, “hxxps://signal-premium-app[.]org.”

According to the Cyble’s report, because the supply code of the apps used to convince victims was open supply, the Bitter APT hacking group had more access to model their attack based on anticipated behavior and standard options. According to reports, links showed attractive women to lure victims into opening phishing links. This would deploy the malware on their systems. Moreover, an open channel, ‘Apple TestFlight’, was used to convince users to download and install their ‘iOS chat application.’

thecyberexpress

View Comments

Recent Posts

The Cyber Express Weekly Roundup: AI Disruption, Regulatory Pressure, and the Evolving Cyber Threat Landscape

AI fraud, deepfake probes, SME cyber warnings, and ransomware cases highlight rising global risks in this week’s Cyber Express roundup.

2 days ago

French National Bank Authority Breach Exposed 1.2 Million Accounts

French national bank authority confirmed a major data breach affecting 1.2 million bank accounts after a malicious actor stole credentials…

2 days ago

What Big Tech Leaders Said On AI’s Future at India AI Impact Summit 2026

The real success of AI will not only depend on how powerful the technology becomes, but on how safely, fairly,…

2 days ago

Two Petabytes Worth Data of Israeli’s Siphoned, Says Cyber Head

Israel data breach totals two petabytes, with phishing up 35% and cyber influence attacks rising 170%, says Yossi Karadi.

2 days ago

Cyberattack Forces Clinic Closures, Surgery Cancellations at University of Mississippi Medical Center

The UMMC cyberattack halted surgeries, closed clinics statewide and triggered a federal probe into potential patient data exposure.

2 days ago

First Android Malware Weaponizes Gemini AI to Evade Detection, Maintain Persistence

ESET researchers discovered PromptSpy, the first known Android malware to integrate generative AI directly into its execution flow, marking a…

3 days ago

This website uses cookies. By continuing to use this website you are giving consent to cookies being used.

Read More