logo

Rapid Response: Zimperium Detects GhostSpy Android RAT

ID: 3f7c257a-1082-529a-8d04-074e0c457afc

STIX ID: report--3f7c257a-1082-529a-8d04-074e0c457afc

Feed Name: Zimperium Blog

Threat Score
75/100

Date Published: 2025-06-03

Date Updated: 2026-05-01

...
...

CYFIRMA uncovered GhostSpy, a highly stealthy and persistent web-based Android Remote Access Trojan that can remotely control infected devices, exfiltrate sensitive information, monitor activity in real time, and resist uninstallation by hiding in seemingly benign apps. Zimperium reports on-device dynamic detections of GhostSpy IOCs — including an instance on an Honor Magic V3 in Singapore (Android 14) impacting a banking app in November 2024 — indicating active in-the-wild presence and targeted risk to mobile users and organizations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.