logo

GhostChat Malware Locks Victims’ Devices, Demands Passcodes for Restoration

ID: 9a21ad67-94c1-534e-81f4-9a7cff9a1e8e

STIX ID: report--9a21ad67-94c1-534e-81f4-9a7cff9a1e8e

Feed Name: GBHackers

Threat Score
70/100

Date Published: 2026-02-03

Date Updated: 2026-04-22

Author: Mayura Kathir

...
...

ESET and other researchers uncovered GhostChat, an Android spyware campaign targeting users in Pakistan by distributing a sideloaded fake dating app that uses hardcoded login/unlock codes and romance-scam profiles to socially engineer victims; once installed the app silently connects to C&C servers to exfiltrate device IDs, contacts and files and continuously monitors for new documents and images. The same infrastructure is tied to Windows DLL/PowerShell payloads and malicious websites that abuse WhatsApp pairing and fake official alerts, and the report includes IOCs and mitigation advice.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.