Rapid Response: Zimperium Detects GhostSpy Android RAT
ID: 3f7c257a-1082-529a-8d04-074e0c457afc
STIX ID: report--3f7c257a-1082-529a-8d04-074e0c457afc
Feed Name: Zimperium Blog
CYFIRMA uncovered GhostSpy, a highly stealthy and persistent web-based Android Remote Access Trojan that can remotely control infected devices, exfiltrate sensitive information, monitor activity in real time, and resist uninstallation by hiding in seemingly benign apps. Zimperium reports on-device dynamic detections of GhostSpy IOCs — including an instance on an Honor Magic V3 in Singapore (Android 14) impacting a banking app in November 2024 — indicating active in-the-wild presence and targeted risk to mobile users and organizations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
