By using this site, you agree to the Privacy Policy and Terms of Use.
Accept
Viral Trending contentViral Trending content
  • Home
  • World News
  • Politics
  • Sports
  • Celebrity
  • Business
  • Crypto
  • Gaming News
  • Tech News
  • Travel
Reading: SpyNote, BadBazaar, MOONSHINE Malware Target Android and iOS Users via Fake Apps
Notification Show More
Viral Trending contentViral Trending content
  • Home
  • Categories
    • World News
    • Politics
    • Sports
    • Celebrity
    • Business
    • Crypto
    • Tech News
    • Gaming News
    • Travel
  • Bookmarks
© 2024 All Rights reserved | Powered by Viraltrendingcontent
Viral Trending content > Blog > Tech News > SpyNote, BadBazaar, MOONSHINE Malware Target Android and iOS Users via Fake Apps
Tech News

SpyNote, BadBazaar, MOONSHINE Malware Target Android and iOS Users via Fake Apps

By Viral Trending Content 6 Min Read
Share
SHARE
SpyNote, BadBazaar, MOONSHINE Malware

Cybersecurity researchers have found that threat actors are setting up deceptive websites hosted on newly registered domains to deliver a known Android malware called SpyNote.

These bogus websites masquerade as Google Play Store install pages for apps like the Chrome web browser, indicating an attempt to deceive unsuspecting users into installing the malware instead.

“The threat actor utilized a mix of English and Chinese-language delivery sites and included Chinese-language comments within the delivery site code and the malware itself,” the DomainTools Investigations (DTI) team said in a report shared with The Hacker News.

SpyNote (aka SpyMax) is a remote access trojan long known for its ability to harvest sensitive data from compromised Android devices by abusing accessibility services. In May 2024, the malware was propagated via another bogus site impersonating a legitimate antivirus solution known as Avast.

Cybersecurity

Subsequent analysis by mobile security firm Zimperium has unearthed similarities between SpyNote and Gigabud, raising the possibility that the same threat actor or actors are behind the two malware families. Gigabud is attributed to a Chinese-speaking threat actor codenamed GoldFactory.

Over the years, SpyNote has also seen some level of adoption by state-sponsored hacking groups, such as OilAlpha and other unknown actors.

SpyNote, BadBazaar, MOONSHINE Malware

The clone websites identified by DTI include a carousel of images that, when clicked, download a malicious APK file onto the user’s device. The package file acts as a dropper to install a second embedded APK payload via the DialogInterface.OnClickListener interface that allows for the execution of the SpyNote malware when an item in a dialog box is clicked.

“Upon installation, it aggressively requests numerous intrusive permissions, gaining extensive control over the compromised device,” DTI said.

“This control allows for the theft of sensitive data such as SMS messages, contacts, call logs, location information, and files. SpyNote also boasts significant remote access capabilities, including camera and microphone activation, call manipulation, and arbitrary command execution.”

SpyNote, BadBazaar, MOONSHINE Malware

The disclosure comes as Lookout revealed that it observed over 4 million mobile-focused social engineering attacks in 2024, with 427,000 malicious apps detected on enterprise devices and 1,600,000 vulnerable app detections during the time period.

“Over the course of the last five years, iOS users have been exposed to significantly more phishing attacks than Android users,” Lookout said. “2024 was the first year where iOS devices were exposed more than twice as much as Android devices.”

Intel Agencies Warn of BadBazaar and MOONSHINE

The findings also follow a joint advisory issued by cybersecurity and intelligence agencies from Australia, Canada, Germany, New Zealand, the United Kingdom, and the United States about the targeting of Uyghur, Taiwanese, and Tibetan communities using malware families such as BadBazaar and MOONSHINE.

Targets of the campaign include non-governmental organizations (NGOs), journalists, businesses, and civil society members who advocate for or represent these groups. “The indiscriminate way this spyware is spread online also means there is a risk that infections could spread beyond intended victims,” the agencies said.

A subset of app icons used by samples of the MOONSHINE surveillance tool as of January 2024

Both BadBazaar and MOONSHINE are classified as trojans that are capable of gathering sensitive data from Android and iOS devices, including locations, messages, photos, and files. They are typically distributed via apps that are passed off as messaging, utilities, or religious apps.

BadBazaar was first documented by Lookout in November 2022, although campaigns distributing the malware are assessed to have been ongoing as early as 2018. MOONSHINE, on the other hand, was recently put to use by a threat actor dubbed Earth Minotaur to facilitate long-term surveillance operations aimed at Tibetans and Uyghurs.

The use of BadBazaar has been tied to a Chinese hacking group tracked as APT15, which is also known as Flea, Nylon Typhoon (formerly Nickel), Playful Taurus, Royal APT, and Vixen Panda.

Cybersecurity

“While the iOS variant of BadBazaar has relatively limited capabilities versus its Android counterpart, it still has the ability to exfiltrate personal data from the victim’s device,” Lookout said in a report published in January 2024. “Evidence suggests that it was primarily targeted at the Tibetan community within China.”

According to the cybersecurity company, data collected from the victims’ devices via MOONSHINE is exfiltrated to an attacker-controlled infrastructure that can be accessed via a so-called SCOTCH ADMIN panel, which displays details of compromised devices and the level of access to each of them. As of January 2024, 635 devices were logged across three SCOTCH ADMIN panels.

In a related development, Swedish authorities have arrested Dilshat Reshit, a Uyghur resident of Stockholm, on suspicion of spying on fellow members of the community in the country. Reshit has served as the World Uyghur Congress’ (WUC) Chinese-language spokesperson since 2004.

Found this article interesting? Follow us on Twitter  and LinkedIn to read more exclusive content we post.

You Might Also Like

The Ultimate Dolby Atmos Experience Might Be In Your Car

Samsung Tri-fold Foldable Named and Dated

AI’s Next Evolution: From Advisor to Architect – New TCS/MIT SMR Study Reveals Game-Changing Shift

9 Best Coolers WIRED Tested for Every Budget, Any Situation

Astronomers observe the earliest moments of a new solar system

TAGGED: Android, Cyber Security, Cybersecurity, data breach, Internet, ios security, Malware, mobile security, phishing, Remote Access Trojan, social engineering, spyware
Share This Article
Facebook Twitter Copy Link
Previous Article Trump faces ‘insider trading’ accusations
Next Article Senator Tim Scott is confident market structure bill passed by August
Leave a comment

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

- Advertisement -
Ad image

Latest News

Crypto Exchange CoinDCX Falls Victim To $44 Million Hack – Details
Crypto
The Ultimate Dolby Atmos Experience Might Be In Your Car
Tech News
Littler fuelled for World Matchplay by 'hours and hours' of practice
Sports
Assassin’s Creed Shadows’ Development Budget Exceeded €100 Million
Gaming News
Asian shares, yen weather Japan uncertainty as earnings loom
Business
Samsung Tri-fold Foldable Named and Dated
Tech News
Ether preps record short squeeze as analysis sees $4K ETH price ‘soon’
Crypto

About Us

Welcome to Viraltrendingcontent, your go-to source for the latest updates on world news, politics, sports, celebrity, tech, travel, gaming, crypto news, and business news. We are dedicated to providing you with accurate, timely, and engaging content from around the globe.

Quick Links

  • Home
  • World News
  • Politics
  • Celebrity
  • Business
  • Home
  • World News
  • Politics
  • Sports
  • Celebrity
  • Business
  • Crypto
  • Gaming News
  • Tech News
  • Travel
  • Sports
  • Crypto
  • Tech News
  • Gaming News
  • Travel

Trending News

cageside seats

Unlocking the Ultimate WWE Experience: Cageside Seats News 2024

Crypto Exchange CoinDCX Falls Victim To $44 Million Hack – Details

Investing £5 a day could help me build a second income of £329 a month!

cageside seats
Unlocking the Ultimate WWE Experience: Cageside Seats News 2024
May 22, 2024
Crypto Exchange CoinDCX Falls Victim To $44 Million Hack – Details
July 21, 2025
Investing £5 a day could help me build a second income of £329 a month!
March 27, 2024
Brussels unveils plans for a European Degree but struggles to explain why
March 27, 2024
© 2024 All Rights reserved | Powered by Vraltrendingcontent
  • About Us
  • Contact US
  • Disclaimer
  • Privacy Policy
  • Terms of Service
Welcome Back!

Sign in to your account

Lost your password?