logo

GhostChat Spyware Attacking Android Users Via WhatsApp to Exfiltrate Sensitive Details

ID: 04a88e4c-4c71-5805-b943-7cf7389604f2

STIX ID: report--04a88e4c-4c71-5805-b943-7cf7389604f2

Feed Name: cybersecurityNews.com

Threat Score
70/100

Date Published: 2026-01-30

Date Updated: 2026-04-21

Author: Tushar Subhra Dutta

...
...

GhostChat is an Android spyware campaign that lures users in Pakistan with fake dating profiles requiring hardcoded unlock codes; victims side-load a malicious app that masquerades as a chat platform while silently harvesting device identifiers, contacts and files, continuously monitoring new images and documents, and exfiltrating data over HTTPS to attacker-controlled servers. The threat uses persistence (BOOT_COMPLETED, foreground service), content observers for ongoing surveillance, and directs victims to WhatsApp numbers run by the operators to facilitate the romance scam.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.