logo

Google Play Used to Spread 'Patchwork' APT's Espionage Apps

ID: ed40e85a-d35a-51fe-82b9-085b4d7d704a

STIX ID: report--ed40e85a-d35a-51fe-82b9-085b4d7d704a

Feed Name: Dark Reading

Threat Score
75/100

Date Published: 2024-02-02

Date Updated: 2026-04-21

Author: Becky Bracken, Editor, Dark Reading

...
...

ESET researchers uncovered an espionage campaign by the Patchwork APT that distributed a new Android RAT called VajraSpy via six malicious Google Play apps (and six more on third-party stores). The trojanized apps—named Privee Talk, MeetMe, Let's Chat, Quick Chat, Rafagat, and Faraqat—were downloaded over 1,400 times, could intercept calls, SMS, files and contacts, extract WhatsApp and Signal messages, record calls and take pictures, and appear to have targeted Pakistani users using honey-trap romance lures; Google removed the apps after ESET reported them.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.