Spyware disguised as emergency-alert app sent to Israeli smartphones
ID: 8268b8ea-029f-51d5-9637-1f061e4e5fae
STIX ID: report--8268b8ea-029f-51d5-9637-1f061e4e5fae
Feed Name: The Register (Security)
Acronis TRU researchers identified a mobile spyware campaign delivering a trojanized version of Israel’s Red Alert app via SMS phishing and shortened links; the fake app uses spoofed certificates and installer metadata to bypass Android checks, requests extensive permissions (including GPS, SMS, contacts), creates phishing overlays to capture OTPs and credentials, persists across reboots, and continuously exfiltrates collected data to a command-and-control server. The activity is likely indiscriminate, was publicly reported by Israeli authorities, and may be linked to the Hamas-aligned Arid Viper APT.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
