Russian army targeted by new Android malware hidden in mapping app
ID: 452a5912-815f-5091-a1d0-bb1b70426ea4
STIX ID: report--452a5912-815f-5091-a1d0-bb1b70426ea4
Feed Name: Bleeping Computer
A trojanized version of the Alpine Quest Android mapping app—distributed via Telegram channels and Russian app catalogs as a cracked Pro build—contains spyware (tracked as Android.Spy.1292.origin) that exfiltrates phone numbers, contacts, geolocation (including real-time tracking), file metadata, and steals documents from messaging apps; Doctor Web discovered the malware and published IOCs. The campaign targets users likely including military personnel using the app for operational planning and can download additional modules to harvest Telegram and WhatsApp data.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
