• Latest
  • Trending
CapraRAT impersonates YouTube to hack Android devices – Dark Reading

CapraRAT impersonates YouTube to hack Android devices – Dark Reading

19.09.2023
Maldivians vote in presidential runoff that will decide whether India or China has power – Yahoo News

Maldivians vote in presidential runoff that will decide whether India or China has power – Yahoo News

30.09.2023
NGX Loses N37 Billion As Investors Panic Sell Stocks To Buy Foreign Exchange – Business Post Nigeria

NGX Loses N37 Billion As Investors Panic Sell Stocks To Buy Foreign Exchange – Business Post Nigeria

30.09.2023
Dominik Szoboszlai gives his approval to brilliant new Liverpool song sung by Reds fan

Dominik Szoboszlai gives his approval to brilliant new Liverpool song sung by Reds fan

30.09.2023

VTech® presents an attractive collection of new products at Toy Fair® 2023

30.09.2023
Call of Duty: Nicki Minaj with the Doom-Kettensäge – Crossover … – ingame.de

Call of Duty: Nicki Minaj with the Doom-Kettensäge – Crossover … – ingame.de

30.09.2023
The 5 Luckiest Chinese Zodiac Signs This Week Starting October 2, 2023 – YourTango

The 5 Luckiest Chinese Zodiac Signs This Week Starting October 2, 2023 – YourTango

30.09.2023
Norwich family evacuated after nearly 50-gallon oil spill in basement

Norwich family evacuated after nearly 50-gallon oil spill in basement

30.09.2023
How to watch Ryder Cup 2023: Live stream, TV channel and competition schedule as Team Europe and Team USA face off again

How to watch Ryder Cup 2023: Live stream, TV channel and competition schedule as Team Europe and Team USA face off again

30.09.2023
Apple Car will soon be available with exciting features that… – LADbible

Apple Car will soon be available with exciting features that… – LADbible

30.09.2023
Venus Williams flaunts leggy legs in a sparkling black mini dress as she steps out of the Costes Hotel during Paris Fashion Week.

Venus Williams flaunts leggy legs in a sparkling black mini dress as she steps out of the Costes Hotel during Paris Fashion Week.

30.09.2023
Katy Perry has ideas for what to do – what to do … – Stara – Viihde, lifestyle ja matkailu

Katy Perry has ideas for what to do – what to do … – Stara – Viihde, lifestyle ja matkailu

30.09.2023
Stewie is back, the Aces are moving forward: the biggest takeaways from the WNBA semifinals – ESPN – ESPN

Stewie is back, the Aces are moving forward: the biggest takeaways from the WNBA semifinals – ESPN – ESPN

30.09.2023
Saturday, September 30, 2023
  • World
  • Economics
  • Sport
    • Basketball
    • Football
    • Nfl
    • Golf
    • F1
    • UFC
  • Technology
  • Culture
    • Arts
  • Media
    • Film
    • Celebs
    • TV
  • LifeStyle
    • Auto
  • Travel
OLTNEWS
  • World
  • Economics
  • Sport
    • Basketball
    • Football
    • Nfl
    • Golf
    • F1
    • UFC
  • Technology
  • Culture
    • Arts
  • Media
    • Film
    • Celebs
    • TV
  • LifeStyle
    • Auto
  • Travel
OLTNEWS
No Result
View All Result

Home » Technology » CapraRAT impersonates YouTube to hack Android devices – Dark Reading

CapraRAT impersonates YouTube to hack Android devices – Dark Reading

19/09/2023 14:57:16
in Technology
0
0
SHARES
Share on WhatsappShare on Facebook

Related posts

VTech® presents an attractive collection of new products at Toy Fair® 2023

30.09.2023
Apple Car will soon be available with exciting features that… – LADbible

Apple Car will soon be available with exciting features that… – LADbible

30.09.2023

A known threat actor linked to Pakistan is using romance-based content lures to deliver Android-based spyware that mimics YouTube in order to hijack Android devices. In this way, malicious actors gain almost complete control over victims’ cell phones for cyberespionage and surveillance purposes.

Researchers at SentinelLabs have identified three Android application packages (APKs) linked to Transparent Tribe’s CapraRAT (a remote access Trojan), they revealed in a blog post published on September 18.

Two of the packages aim to trick users into downloading what they think is the legitimate YouTube app, and a third uses romance-based social engineering by contacting a YouTube channel owned by a character called “Piya Sharma”, who includes uploads of several short clips of a woman in various locations.

“These apps mimic the look and feel of YouTube, although they are less feature-rich than the legitimate native YouTube Android app,” Alex Delamotte, a security researcher at SentinelLabs, wrote in the post.

Transparent Tribe, also known as APT36 and Earth Karkaddan, is a Pakistani threat group active since 2013 that typically targets military and diplomatic personnel in India and Pakistan, with more recent campaigns targeting the Indian education sector. The group has also been active during the COVID-19 pandemic as part of a wave of attacks against remote workers.

Hiding in Malicious Android Apps

Transparent Tribe tends to use Android-based spyware in its attacks, although it also hides malicious payloads behind malicious Office documents. CapraRAT, discovered and named by TrendMicro early last year, is the group’s latest weapon of choice against Android users with a particularly identifiable structure: the malware is apparently an Android framework that hides RAT functionality in another application.

Transparent Tribe distributes malware-spreading Android apps outside of the Google Play Store, relying on self-managed websites and social engineering to convince users to install a weaponized app. As part of a campaign launched earlier this year, the group also distributed CapraRAT through Android apps disguised as a dating service, which became a common bait theme for spreading the malware.

“The group’s decision to create a YouTube-like app is a new addition to a known trend by the group of weaponizing Android apps with spyware and distributing them to targets via social media,” Delamotte wrote.

Transparent Tribe has used CapraRAT primarily against targets who have knowledge or information related to cases involving the disputed region of Kashmir, as well as human rights activists working on Pakistan-related issues, she added. .

CapraRAT does RAT things

Researchers identified and analyzed three YouTube-themed CapraRAT APKs: two disguised as YouTube itself that borrow the video-sharing service’s icon, and the third called Piya Sharma that uses the character’s image and likeness YouTube mentioned previously.

“This theme suggests that the actor continues to use romance-based social engineering techniques to convince his targets to install the apps, and that Piya Sharma is a similar character,” Delamotte wrote.

Once downloaded, the malicious app requests several permissions on the device, some of which make sense for YouTube, such as taking photos and videos and accessing the microphone. Other requested permissions, such as the ability to send, receive and read SMS messages, reflect CapraRAT’s bad intent.

Other features of CapraRAT on a compromised Android device include: searching for accounts on the device; access contact lists; and read, modify and/or delete the contents of a device’s SD card.

When the app is launched, it uses a WebView object to load the YouTube website in a different way than the native YouTube app for Android. In fact, it’s “more akin to viewing the YouTube page in a mobile web browser,” Delamotte wrote.

Android Spyware Defense Measures

SentinelLabs warns individuals and organizations linked to diplomatic, military or activist issues in India or Pakistan to be wary of attacks by Transparent Tribe, and in particular of YouTube impersonation as part of this campaign to attract the victims.

Android users should never install Android apps distributed outside the Google Play Store itself and also avoid downloading new social media apps advertised within social media communities.

In addition to these common-sense measures, users should also evaluate the permissions requested by an app they download, especially for new or previously unknown apps, to ensure they are not exposed to risks. . In addition, SentinelLabs advises them to never install a third-party version of an application already present on their device.

Previous Post

Best NFL Football KO, Survivor Picks, Strategy, Tips for Week 3, 2023: Fade the Bengals

Next Post

Boost Bayern Munich vs Manchester United: Get 45/1 for Rashford to have a shot on target with Paddy Power

Related Posts

Technology

VTech® presents an attractive collection of new products at Toy Fair® 2023

30.09.2023
0

Award-Winning Product Lines Introduce New Additions NEW YORK, September 30, 2023 /PRNewswire/ -- Today, VTech® will showcase its line of...

Read more
Apple Car will soon be available with exciting features that… – LADbible

Apple Car will soon be available with exciting features that… – LADbible

30.09.2023
The incredible high-end Samsung Galaxy Buds 2 Pro are currently 30% off their price at Amazon – PhoneArena

The incredible high-end Samsung Galaxy Buds 2 Pro are currently 30% off their price at Amazon – PhoneArena

30.09.2023

macOS Sonoma: how to add a widget to Mac writing – 01Net

30.09.2023

Which Android phones will no longer support WhatsApp starting October 24? – The logical Indian

30.09.2023

MAGNA-TILES® Downhill Duo Set Wins Preschool Toy of the Year at the 2023 Toy of the Year Awards

30.09.2023
Load More
Next Post
Boost Bayern Munich vs Manchester United: Get 45/1 for Rashford to have a shot on target with Paddy Power

Boost Bayern Munich vs Manchester United: Get 45/1 for Rashford to have a shot on target with Paddy Power

Recent Posts

  • Maldivians vote in presidential runoff that will decide whether India or China has power – Yahoo News
  • NGX Loses N37 Billion As Investors Panic Sell Stocks To Buy Foreign Exchange – Business Post Nigeria
  • Dominik Szoboszlai gives his approval to brilliant new Liverpool song sung by Reds fan
  • VTech® presents an attractive collection of new products at Toy Fair® 2023
  • Call of Duty: Nicki Minaj with the Doom-Kettensäge – Crossover … – ingame.de

Archives

  • September 2023
  • August 2023
  • July 2023
  • April 2023
  • March 2023
  • February 2023
  • January 2023
  • December 2022
  • November 2022
  • October 2022
  • September 2022
  • August 2022
  • July 2022
  • June 2022
  • May 2022
  • April 2022
  • March 2022
  • February 2022
  • January 2022
  • December 2021
  • November 2021
  • October 2021
  • September 2021
  • August 2021
  • July 2021
  • June 2021
  • May 2021
  • April 2021
  • March 2021
  • February 2021
  • January 2021
  • December 2020
  • November 2020
  • October 2020
  • September 2020
  • August 2020
  • July 2020
  • June 2020
  • May 2020
  • April 2020
  • March 2020
  • EN

© 2020

No Result
View All Result
  • World
  • Economics
  • Sport
    • Basketball
    • Football
    • Nfl
    • Golf
    • F1
    • UFC
  • Technology
  • Culture
    • Arts
  • Media
    • Film
    • Celebs
    • TV
  • LifeStyle
    • Auto
  • Travel

© 2020

This website uses cookies. By continuing to use this website you are giving consent to cookies being used. Visit our Privacy and Cookie Policy.