eXotic Visit campaign: Tracing the footprints of Virtual Invaders
ID: d312b11d-4455-5a85-aa3f-60ab7c93fdd2
STIX ID: report--d312b11d-4455-5a85-aa3f-60ab7c93fdd2
Feed Name: WeLiveSecurity (ESET Research)
ESET documents the eXotic Visit campaign (Nov 2021–end of 2023) in which threat actors tracked as "Virtual Invaders" distributed trojanized Android apps (messaging and utility) via dedicated websites and Google Play that embed customized XploitSPY to exfiltrate contacts, files, audio, GPS, and intercept notifications; the report includes technical analysis (native library obfuscation, emulator detection, Firebase/ngrok C2), IoCs (SHA-1s, domains, IPs), victimology (primarily Pakistan and India, ~380 compromised accounts), and notes that Google removed the malicious apps after disclosure.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
