GhostChat Spyware Targets Android Users Through WhatsApp, Steals Sensitive Data
ID: 4a255242-17ed-56d0-8df3-95b0cee08810
STIX ID: report--4a255242-17ed-56d0-8df3-95b0cee08810
Feed Name: GBHackers
GhostChat is an Android spyware campaign targeting users in Pakistan with romance-scam lures delivered via a sideloaded fake dating app; once installed it exfiltrates device IDs, contacts, photos and documents, and facilitates WhatsApp hijacking. The report includes technical details (sample SHA-1, C2 IP 188.114.96.10), associated Windows DLL/PowerShell infrastructure, observed polling/exfiltration behavior, and defensive recommendations such as blocking unknown APK installs and monitoring WhatsApp linked devices.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
