logo

RedAlert Mobile Espionage Campaign Exploits Trojanized Rocket Alert App to Spy on Civilians

ID: d9f6e24b-cc76-5811-b65c-f25572ff1b42

STIX ID: report--d9f6e24b-cc76-5811-b65c-f25572ff1b42

Feed Name: GBHackers

Threat Score
78/100

Date Published: 2026-03-05

Date Updated: 2026-04-22

Author: Mayura Kathir

...
...

Researchers uncovered an active mobile espionage campaign named RedAlert that lures users into sideloading a trojanized version of Israel’s official rocket-alert app via SMS phishing; the malicious APK spoofs signing and installer origin, dynamically loads a hidden asset, and executes a DEX-based spyware payload that exfiltrates SMS, contacts and live GPS to attacker-controlled C2 servers. The report details the three-stage infection chain, persistence and PKI spoofing techniques, lists C2 domains and IPs, and warns users to avoid sideloading and verify apps via trusted stores.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.