logo

VajraSpy: A Patchwork of espionage apps

ID: 0b1b7a55-9a3a-5803-93c7-0775f008e4c9

STIX ID: report--0b1b7a55-9a3a-5803-93c7-0775f008e4c9

Feed Name: WeLiveSecurity (ESET Research)

Threat Score
78/100

Date Published: 2024-02-01

Date Updated: 2026-05-01

...
...

ESET Research uncovered a targeted espionage campaign attributed with high confidence to the Patchwork APT involving 12 Android apps bundled with the VajraSpy RAT; six were distributed through Google Play (over 1,400 installs) and six were found in the wild. The malware exfiltrates contacts, SMS, call logs, files, notifications and—when granted accessibility privileges—WhatsApp/Signal messages, and in some variants can record calls, capture audio/video, perform keylogging, and scan Wi‑Fi; operators used Firebase and other C2 servers and the report includes hashes, domains/IPs, victim geolocation (148 devices) and MITRE ATT&CK mappings.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.