GhostChat Malware Locks Victims’ Devices, Demands Passcodes for Restoration
ID: 9a21ad67-94c1-534e-81f4-9a7cff9a1e8e
STIX ID: report--9a21ad67-94c1-534e-81f4-9a7cff9a1e8e
Feed Name: GBHackers
ESET and other researchers uncovered GhostChat, an Android spyware campaign targeting users in Pakistan by distributing a sideloaded fake dating app that uses hardcoded login/unlock codes and romance-scam profiles to socially engineer victims; once installed the app silently connects to C&C servers to exfiltrate device IDs, contacts and files and continuously monitors for new documents and images. The same infrastructure is tied to Windows DLL/PowerShell payloads and malicious websites that abuse WhatsApp pairing and fake official alerts, and the report includes IOCs and mitigation advice.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
