Bahamut Threat Group Targets Users With Phishing
ID: 1d49a66f-5902-5c40-9873-a25defdc8a43
STIX ID: report--1d49a66f-5902-5c40-9873-a25defdc8a43
Feed Name: Cyble Blog
This Cyble report details a phishing campaign distributing Bahamut Android spyware disguised as Jamaat chat apps; the APK (SHA256 9d4e5d46...) requests many dangerous permissions (contacts, SMS, call logs, audio, camera, location), stores collected data locally, and exfiltrates it to a Socket.IO/HTTPS C2 at https://h94xnghlldx6a862moj3.de. The report includes technical code-level analysis of data collection and scheduling, multiple additional SHA256 hashes and the C2 URL as IoCs, and mitigation recommendations such as uninstalling the app, using official app stores, and updating AV and systems.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
