RedAlert Mobile Espionage Campaign Targets Civilians with Trojanized Rocket Alert App for Surveillance
ID: 37ed09ff-7606-5588-b49a-5088a15fa5bd
STIX ID: report--37ed09ff-7606-5588-b49a-5088a15fa5bd
Feed Name: cybersecurityNews.com
CloudSEK reports a high-risk mobile espionage campaign that distributed a trojanized version of Israel’s Red Alert app via smishing to induce victims to sideload RedAlert.apk. The malicious app presents a legitimate alert UI while requesting high-risk permissions (READ_SMS, READ_CONTACTS, ACCESS_FINE_LOCATION), uses package manager hooking and dynamic Dex loading in a three-stage chain, and exfiltrates harvested data via HTTP POST to https://api.ra-backup.com/analytics/submit.php (noted C2 IP 216.45.58.148); recommended mitigations include removing the app, factory reset, blocking the domain/IP, disabling sideloading, and flagging apps with the listed permission set.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
