Mobile spyware campaign impersonates Israel's Red Alert rocket warning system
ID: 8b6f9c99-5ada-595d-a0b6-e41d573da4ec
STIX ID: report--8b6f9c99-5ada-595d-a0b6-e41d573da4ec
Feed Name: TRU Security by Acronis
Acronis TRU identified a targeted smishing campaign delivering a trojanized Red Alert Android APK to Israeli users that maintains legitimate alert functionality while running a hidden spyware component; the malware abuses SMS/contacts/location/accounts/overlay permissions, implements certificate spoofing and a dual-stage loader to evade detection, and exfiltrates harvested data to https://api.ra-backup.com/analytics/submit.php, with MITRE ATT&CK mappings and mitigations provided.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
