logo

Israel: RedAlert Spyware Campaign Exploits Wartime Panic With Trojanized App

ID: 75f51bec-cefb-5f81-be16-d026df3406f2

STIX ID: report--75f51bec-cefb-5f81-be16-d026df3406f2

Feed Name: Infosecurity Magazine (News)

Threat Score
78/100

Date Published: 2026-03-03

Date Updated: 2026-04-22

...
...

**Executive Summary:** A sophisticated mobile espionage campaign is distributing a trojanized version of Israel’s Red Alert rocket-warning app via SMS phishing and sideloading; the multi-stage Android spyware spoofs the legitimate app, requests dangerous permissions (SMS, contacts, precise GPS), persistently harvests and stages data locally, and exfiltrates it to attacker-controlled infrastructure (observed C2: api.ra-backup.com through AWS/Cloudflare).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.