RedAlert Mobile Espionage Campaign Exploits Trojanized Rocket Alert App to Spy on Civilians
ID: d9f6e24b-cc76-5811-b65c-f25572ff1b42
STIX ID: report--d9f6e24b-cc76-5811-b65c-f25572ff1b42
Feed Name: GBHackers
Researchers uncovered an active mobile espionage campaign named RedAlert that lures users into sideloading a trojanized version of Israel’s official rocket-alert app via SMS phishing; the malicious APK spoofs signing and installer origin, dynamically loads a hidden asset, and executes a DEX-based spyware payload that exfiltrates SMS, contacts and live GPS to attacker-controlled C2 servers. The report details the three-stage infection chain, persistence and PKI spoofing techniques, lists C2 domains and IPs, and warns users to avoid sideloading and verify apps via trusted stores.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
