logo

Bahamut Malware Returns With New Spying Features

ID: 383b35dc-00a3-5970-910d-160e8c509fee

STIX ID: report--383b35dc-00a3-5970-910d-160e8c509fee

Feed Name: Cyble Blog

Threat Score
75/100

Date Published: 2025-11-17

Date Updated: 2026-07-16

...
...

Bahamut, an APT group, resurfaced in April 2022 with a new Android spyware variant distributed via professionally designed phishing sites masquerading as secure messaging apps; the malicious APK (com.chat.services) abuses Accessibility and multiple sensitive permissions to capture data from messaging apps (Viber, Telegram, WhatsApp, Signal, etc.), contacts, SMS, call logs, audio and files, and exfiltrates stolen data to identified C2 servers. The report provides technical analysis, APK metadata and hashes, targeted package names, MITRE ATT&CK mappings, IOCs (URLs and hashes), and recommended mitigations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.