#1 Trending Cybersecurity News & Magazine
Wednesday, September 27, 2023
No Result
View All Result
The Cyber Express
  • MagazineDownload
  • Firewall Daily
    • All
    • Dark Web News
    • Data Breach News
    • Hacking News
    • Ransomware News
    • Vulnerabilities
    ZenLedger data sale

    ZenLedger Data Leak Claim Surfaces on the Dark Web

    CACTUS Cyber Attack

    Unraveling the CACTUS Ransomware Group’s Recent Exploits

    MOVEit Breach Statistics

    Zero-Day Exploitation Impact: MOVEit Breach Statistics Reach 2,120 Organization

    MEDUSA Cyber Attack

    MEDUSA Ransomware Group Strikes Again: Italian Company and Canadian Firm Latest Victims

    Ferguson Wellman cyber attack

    50 Targets and Counting: LostTrust Claims Ferguson Wellman Cyber Attack

    Iran Telecom Cyber Attack

    Iran Telecom Cyber Attack: APT IRAN Claims Access to 4TB of Data

    BORN Data Breach

    Ontario Grapples with Unprecedented Data Breach Impacting Newborn Care Registries

    Sony Data Leak

    “Major Nelson” Claims Sony Data Leak Alleging RansomedVC Lied

    Waterloo Media Data Breach

    Waterloo Media Faces Data Breach by NoEscape Ransomware Group

    Trending Tags

    • blackbyte ransomware
    • Ransomware
    • lapsus$ ransomware
    • Apple
    • Apple vulnerability
  • Essentials
    • All
    • Compliance
    • Governance
    • Policy Updates
    • Regulations
    US Cybersecurity Regulations: Tracing the Past and Predicting the Future

    US Cybersecurity Regulations: Tracing the Past and Predicting the Future

    threat landscape

    The Three Trends to Watch in the Growing Threat Landscape

    Mandatory Dark Web Monitoring for Indian Companies: SEBI Bolsters Cybersecurity Measures

    Mandatory Dark Web Monitoring for Indian Companies: SEBI Bolsters Cybersecurity Measures

    Tesla Data Leak

    Massive Tesla Data Leak Exposing Over 75000 Staff Attributed to Former Employees

    Cybersecurity Primer

    Bridging the Gap: Cybersecurity Primer to Address Woes Surrounding US Government Officials

    Executive order for cybersecurity

    White House Directs Federal Agencies to Enhance Cybersecurity Amid Exposure Concerns

    AI Cyber Challenge

    Biden-Harris Administration Introduces AI Cyber Challenge, Offering $20 Million Reward

    aws agent hijack

    New Research Exposes Advanced Cyber Threat – Attackers Hijack AWS Agent to Control Endpoints

    HUB cyber security

    Investors Sue HUB Cyber Security for Misleading Statements on Mount Rainier Merger

    • Regulations
    • Compliance
    • Governance
    • Policy Updates
  • Features
    • Cyber Warfare
    • Espionage
    • Workforce
      • Learning & Development
  • Business
    • All
    • Appointments
    • Budgets
    • Mergers & Aquisitions
    • Partnerships
    • Press Release
    • Startups
    Countdown to TimeAI Summit 2023

    Countdown to TimeAI Summit 2023: Unveiling the Future of Artificial Intelligence in Dubai

    Emerging Tech Summit

    The Emerging Tech Summit – Saudi Arabia 2023

    Business Cybersecurity

    Prioritizing Business Cybersecurity Plans During Mergers and Acquisitions

    TimeAI Summit

    TimeAI Summit is Uniting Tech Giants and Visionaries in Dubai to Shape the Future of AI

    CyberDSA 2023

    CyberDSA 2023: Forging a Resilient Digital Future Through Unprecedented Collaboration

    Summit MENA 2023

    MENA Summit 2023: Exploring the Future of Digital Identity & Authentication

    Cyble Raises 24 Million in Series B Funding

    Cyble Raises 24 Million in Series B Funding: Leveraging AI and Threat Intelligence to Revolutionize Cybersecurity

    Alarming 66% Quarterly Growth in Ransomware Attacks Notes Cyble’s Q2-2023 Ransomware Report

    Alarming 66% Quarterly Growth in Ransomware Attacks Notes Cyble’s Q2-2023 Ransomware Report

    Bureau Raises $16.5M in Series A Funding

    Bureau Raises $16.5M in Series A Funding to Drive Global Expansion and Combat Cyber Fraud

    • Startups
    • Mergers & Aquisitions
    • Partnerships
    • Appointments
    • Budgets
    • Research
      • Whitepapers
      • Sponsored Content
      • Market Reports
    • Interviews
      • Podcast
  • EventsCyberCon
    • World CyberCon India 2023
    •  Cyber Security Webinar
    • Endorsed Events
  • ProductsTools
    • Cyble Vision
    • Cyble Hawk (LEA, Govt.)
    • Am I Breached
    • Cyble Odin (Beta)
SUBSCRIBE
  • MagazineDownload
  • Firewall Daily
    • All
    • Dark Web News
    • Data Breach News
    • Hacking News
    • Ransomware News
    • Vulnerabilities
    ZenLedger data sale

    ZenLedger Data Leak Claim Surfaces on the Dark Web

    CACTUS Cyber Attack

    Unraveling the CACTUS Ransomware Group’s Recent Exploits

    MOVEit Breach Statistics

    Zero-Day Exploitation Impact: MOVEit Breach Statistics Reach 2,120 Organization

    MEDUSA Cyber Attack

    MEDUSA Ransomware Group Strikes Again: Italian Company and Canadian Firm Latest Victims

    Ferguson Wellman cyber attack

    50 Targets and Counting: LostTrust Claims Ferguson Wellman Cyber Attack

    Iran Telecom Cyber Attack

    Iran Telecom Cyber Attack: APT IRAN Claims Access to 4TB of Data

    BORN Data Breach

    Ontario Grapples with Unprecedented Data Breach Impacting Newborn Care Registries

    Sony Data Leak

    “Major Nelson” Claims Sony Data Leak Alleging RansomedVC Lied

    Waterloo Media Data Breach

    Waterloo Media Faces Data Breach by NoEscape Ransomware Group

    Trending Tags

    • blackbyte ransomware
    • Ransomware
    • lapsus$ ransomware
    • Apple
    • Apple vulnerability
  • Essentials
    • All
    • Compliance
    • Governance
    • Policy Updates
    • Regulations
    US Cybersecurity Regulations: Tracing the Past and Predicting the Future

    US Cybersecurity Regulations: Tracing the Past and Predicting the Future

    threat landscape

    The Three Trends to Watch in the Growing Threat Landscape

    Mandatory Dark Web Monitoring for Indian Companies: SEBI Bolsters Cybersecurity Measures

    Mandatory Dark Web Monitoring for Indian Companies: SEBI Bolsters Cybersecurity Measures

    Tesla Data Leak

    Massive Tesla Data Leak Exposing Over 75000 Staff Attributed to Former Employees

    Cybersecurity Primer

    Bridging the Gap: Cybersecurity Primer to Address Woes Surrounding US Government Officials

    Executive order for cybersecurity

    White House Directs Federal Agencies to Enhance Cybersecurity Amid Exposure Concerns

    AI Cyber Challenge

    Biden-Harris Administration Introduces AI Cyber Challenge, Offering $20 Million Reward

    aws agent hijack

    New Research Exposes Advanced Cyber Threat – Attackers Hijack AWS Agent to Control Endpoints

    HUB cyber security

    Investors Sue HUB Cyber Security for Misleading Statements on Mount Rainier Merger

    • Regulations
    • Compliance
    • Governance
    • Policy Updates
  • Features
    • Cyber Warfare
    • Espionage
    • Workforce
      • Learning & Development
  • Business
    • All
    • Appointments
    • Budgets
    • Mergers & Aquisitions
    • Partnerships
    • Press Release
    • Startups
    Countdown to TimeAI Summit 2023

    Countdown to TimeAI Summit 2023: Unveiling the Future of Artificial Intelligence in Dubai

    Emerging Tech Summit

    The Emerging Tech Summit – Saudi Arabia 2023

    Business Cybersecurity

    Prioritizing Business Cybersecurity Plans During Mergers and Acquisitions

    TimeAI Summit

    TimeAI Summit is Uniting Tech Giants and Visionaries in Dubai to Shape the Future of AI

    CyberDSA 2023

    CyberDSA 2023: Forging a Resilient Digital Future Through Unprecedented Collaboration

    Summit MENA 2023

    MENA Summit 2023: Exploring the Future of Digital Identity & Authentication

    Cyble Raises 24 Million in Series B Funding

    Cyble Raises 24 Million in Series B Funding: Leveraging AI and Threat Intelligence to Revolutionize Cybersecurity

    Alarming 66% Quarterly Growth in Ransomware Attacks Notes Cyble’s Q2-2023 Ransomware Report

    Alarming 66% Quarterly Growth in Ransomware Attacks Notes Cyble’s Q2-2023 Ransomware Report

    Bureau Raises $16.5M in Series A Funding

    Bureau Raises $16.5M in Series A Funding to Drive Global Expansion and Combat Cyber Fraud

    • Startups
    • Mergers & Aquisitions
    • Partnerships
    • Appointments
    • Budgets
    • Research
      • Whitepapers
      • Sponsored Content
      • Market Reports
    • Interviews
      • Podcast
  • EventsCyberCon
    • World CyberCon India 2023
    •  Cyber Security Webinar
    • Endorsed Events
  • ProductsTools
    • Cyble Vision
    • Cyble Hawk (LEA, Govt.)
    • Am I Breached
    • Cyble Odin (Beta)
No Result
View All Result
The Cyber Express
No Result
View All Result
Home Firewall Daily

Turkish Government Website Spreads Android RAT, Or So You Think!

Cyble Research & Intelligence Labs (CRIL) has uncovered a phishing site that not only aims to deceive unsuspecting users but also distributes a dangerous Android Remote Access Trojan

Chandu Gopalakrishnan by Chandu Gopalakrishnan
July 11, 2023
in Firewall Daily, Malware News
0
Turkish Government website spreads Android RAT
604
SHARES
3.4k
VIEWS
Share on LinkedInShare on Twitter

You might also like

ZenLedger Data Leak Claim Surfaces on the Dark Web

Unraveling the CACTUS Ransomware Group’s Recent Exploits

Zero-Day Exploitation Impact: MOVEit Breach Statistics Reach 2,120 Organization

Turkish Government website spreads Android RAT! Well, that’s what the cybercriminals wanted us to believe.

Cyble Research & Intelligence Labs (CRIL) has uncovered a phishing site that spoofs the Turkish Government website, which deceives unsuspecting users and distributes a dangerous Android Remote Access Trojan (RAT).

The phishing site, hxxps://scanyalx[.]online, masquerades as a legitimate government platform from Turkey, specifically impersonating the e-Devlet kapısı (turkiye.gov.tr) website.

The e-Devlet kapısı is a genuine government site in Turkey, providing citizens with access to various government services, including social security documents, forensic clearance, traffic bills, tax debts, and more.

According to the CRIL report, the RAT’s ability to establish unauthorized access to infected devices, monitor user activity through keylogging, and control the device remotely through VNC poses significant risks to the privacy and security of victims.

Such malicious activities can result in the theft of sensitive personal and financial information, unauthorized access to confidential data, and potential compromise of other devices connected to the same network.

Turkish Government website spreads Android RAT
Phishing site impersonating Turkish Government website. Image: CRIL

Spoof Turkish Government Website Spreads Android RAT

The highly unlikely situation, where a Turkish Government website spreads Android RAT, was created exploiting the trust associated with the official platform with a replica.

Threat actors behind the campaign have crafted a deceptive phishing site that closely resembles the genuine government website, making it difficult for users to discern the fraudulent nature of the site.

The phishing site implements a clever tactic to deceive users by prompting them to verify returns for the Card Fee Payment System, requiring them to provide their identity information.

Upon entering their credentials, victims are redirected to another webpage displaying an alert regarding an outstanding amount of “5420 TL” (Turkish Lira). To receive an immediate refund for the payment, victims are instructed to download an application from the site.

Upon clicking the “Click to Download” button, the phishing site initiates the download of a malicious APK file named “edevletiadesistemi.apk.”

Interestingly, it has been observed that the malicious APK file is downloaded with different names, such as “edevlet.apk” and “cimer.apk,” each time victims enter their credentials and visit the download page.

“Upon further examination of the downloaded malicious file, it has been determined that the malware is a RAT that operates based on commands received from a Command and Control (C&C) server,” said the CRIL report.

“What makes this RAT particularly dangerous is its advanced functionality, including features such as VNC (Virtual Network Computing) and keylogging, enabling it to carry out a wide range of malicious activities covertly without raising suspicion.”

Technical analysis of the malicious APK file

In a deceptively simple process, victims are instructed to download an application from the site.

When the app is run, it unpacks a file called “classes2.dex” from the assets folder. This file contains classes that were missing from the main application file. The app uses this additional file to load the necessary classes and function properly.

After installation, the app loads an HTML file named “pmuxmlpr.html” from the assets folder. This file is displayed within a WebView, showing a message to the user. The message asks the user to complete an application and make an inquiry.

When the user clicks on the message, the app prompts the user to enable the Accessibility service on their device. Once enabled, the app exploits this service to carry out its malicious activities without the user’s knowledge.

These activities include preventing uninstallation, keylogging (recording keystrokes), and granting permissions without user consent, said the report.

The app establishes communication with a Telegram account link to fetch the address of a Command and Control (C&C) server. It tries multiple links until it finds an active C&C server. The C&C server is used for further operations and malicious activities.

The RAT (Remote Access Trojan) performs various malicious actions based on commands received from the C&C server.

These actions include starting a Virtual Network Computing (VNC) service, stealing SMS messages, executing commands, collecting keylogs, launching or deleting applications, sending SMS messages, collecting contacts, and more. The RAT heavily relies on the Accessibility service to carry out these activities.

By incorporating VNC functionality, the RAT gains the ability to execute unauthorized transactions, exfiltrate sensitive data, and interact with the user interface of targeted applications.

The RAT also manipulates the clipboard’s content, initiates phone calls, and collects personally identifiable information (PII) from the infected device. The stolen data is transmitted back to the C&C server.

Overall, the RAT is fully operational and capable of carrying out various malicious activities, compromising the privacy and security of the infected device and the unsuspecting user who fell for the spurious Turkish Government website spreading Android RAT.

Share this:

  • Click to share on LinkedIn (Opens in new window)
  • Click to share on Reddit (Opens in new window)
  • Click to share on Twitter (Opens in new window)
  • Click to share on Facebook (Opens in new window)
  • More
  • Click to email a link to a friend (Opens in new window)
  • Click to share on WhatsApp (Opens in new window)

Related

Tags: Turkish Government website spreads Android RAT
Previous Post

Lockheed Martin Cyber Attack: Türk Hack Team Targets US Defense Giant

Next Post

Radisson Hotels Americas Cyber Attack Traced to CL0P’s Exploitation of MOVEit

Chandu Gopalakrishnan

Chandu Gopalakrishnan

Executive Editor, The Cyber Express

Related Posts

ZenLedger data sale
Firewall Daily

ZenLedger Data Leak Claim Surfaces on the Dark Web

by Vishwa Pandagle
September 27, 2023
CACTUS Cyber Attack
Firewall Daily

Unraveling the CACTUS Ransomware Group’s Recent Exploits

by Ashish Khaitan
September 27, 2023
MOVEit Breach Statistics
Data Breach News

Zero-Day Exploitation Impact: MOVEit Breach Statistics Reach 2,120 Organization

by Vishwa Pandagle
September 27, 2023
MEDUSA Cyber Attack
Firewall Daily

MEDUSA Ransomware Group Strikes Again: Italian Company and Canadian Firm Latest Victims

by Ashish Khaitan
September 27, 2023
Ferguson Wellman cyber attack
Firewall Daily

50 Targets and Counting: LostTrust Claims Ferguson Wellman Cyber Attack

by Vishwa Pandagle
September 27, 2023
Next Post
Radisson Hotels Americas Cyber Attack

Radisson Hotels Americas Cyber Attack Traced to CL0P’s Exploitation of MOVEit

Latest Issue is Out. Subscribe Now



Follow Us On Google News

Latest Cyber News

ZenLedger data sale
Firewall Daily

ZenLedger Data Leak Claim Surfaces on the Dark Web

September 27, 2023
CACTUS Cyber Attack
Firewall Daily

Unraveling the CACTUS Ransomware Group’s Recent Exploits

September 27, 2023
MOVEit Breach Statistics
Data Breach News

Zero-Day Exploitation Impact: MOVEit Breach Statistics Reach 2,120 Organization

September 27, 2023
MEDUSA Cyber Attack
Firewall Daily

MEDUSA Ransomware Group Strikes Again: Italian Company and Canadian Firm Latest Victims

September 27, 2023

Categories

Web Stories

Top 10 CISOs to Follow in 2023
Top 10 CISOs to Follow in 2023
Top 10 Ransomware Gangs in 2023
Top 10 Ransomware Gangs in 2023
Top 5 IoT Security Risks in 2023
Top 5 IoT Security Risks in 2023
Top 10 CTF Platforms in 2023
Top 10 CTF Platforms in 2023
Types of Risks Covered by Cyber Insurance
Types of Risks Covered by Cyber Insurance

About

The Cyber Express by Cyble

#1 Trending Cybersecurity News and Magazine

The Cyber Express  by Cyble is a handbook for all stakeholders of the internet that provides information security professionals with the latest news, updates and knowledge they need to combat cyber threats.

 

Contact

For editorial queries: [email protected]

For marketing and Sales: [email protected]

For Events & Conferences related information: [email protected]

 

Quick Links

  • About Us
  • Advertise With Us
  • Contact Us
  • Editorial Calendar

Our Address

We’re remote friendly, with office locations around the world:

San Francisco, Atlanta, Rome,
Dubai, Mumbai, Bangalore, Hyderabad,  Singapore, Jakarta, Sydney, and Melbourne

 

Headquarters:

The Cyber Express LLC
555 North Point Center E
Alpharetta, GA 30022, USA.

 

India Office:

Cyber Express Media Network
HD-021, 4th Floor, C Wing, Building No.4. Nesco IT Park, WE Highway, Goregaon East, Mumbai, Maharashtra, India – 4000063

Subscribe to Our Feed

RSS Feeds

Follow Us On Google News
  • Privacy Statement
  • Terms of Use
  • Write For Us

© 2023 The Cyber Express (Cybersecurity News and Magazine) | By Cyble Inc.

No Result
View All Result
  • Magazine
  • Firewall Daily
  • Essentials
    • Regulations
    • Compliance
    • Governance
    • Policy Updates
  • Features
    • Cyber Warfare
    • Espionage
    • Workforce
      • Learning & Development
  • Business
    • Startups
    • Mergers & Aquisitions
    • Partnerships
    • Appointments
    • Budgets
    • Research
      • Whitepapers
      • Sponsored Content
      • Market Reports
    • Interviews
      • Podcast
  • Events
    • World CyberCon India 2023
    •  Cyber Security Webinar
    • Endorsed Events
  • Products
    • Cyble Vision
    • Cyble Hawk (LEA, Govt.)
    • Am I Breached
    • Cyble Odin (Beta)

© 2023 The Cyber Express (Cybersecurity News and Magazine) | By Cyble Inc.

Welcome Back!

Login to your account below

Forgotten Password?

Retrieve your password

Please enter your username or email address to reset your password.

Log In

Add New Playlist

This website uses cookies. By continuing to use this website you are giving consent to cookies being used. Visit our Privacy and Cookie Policy.
Top 10 CISOs to Follow in 2023 Top 10 Ransomware Gangs in 2023 Top 5 IoT Security Risks in 2023 Top 10 CTF Platforms in 2023 Types of Risks Covered by Cyber Insurance