GhostChat Spyware Attacking Android Users Via WhatsApp to Exfiltrate Sensitive Details
ID: 04a88e4c-4c71-5805-b943-7cf7389604f2
STIX ID: report--04a88e4c-4c71-5805-b943-7cf7389604f2
Feed Name: cybersecurityNews.com
GhostChat is an Android spyware campaign that lures users in Pakistan with fake dating profiles requiring hardcoded unlock codes; victims side-load a malicious app that masquerades as a chat platform while silently harvesting device identifiers, contacts and files, continuously monitoring new images and documents, and exfiltrating data over HTTPS to attacker-controlled servers. The threat uses persistence (BOOT_COMPLETED, foreground service), content observers for ongoing surveillance, and directs victims to WhatsApp numbers run by the operators to facilitate the romance scam.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
