Fake Balochi Shayri App Targets Ethnic Users
ID: 836f3259-fd61-5f3b-a9d1-98cd39b266af
STIX ID: report--836f3259-fd61-5f3b-a9d1-98cd39b266af
Feed Name: Cyble Blog
Executive Summary: Cyble Research Labs analyzed an Android spyware APK masquerading as a Balochi poetry app that runs headless and exfiltrates contacts, SMS, call logs, files, audio, camera images and screenshots to a remote C2 (SHA256: afc9fbb1ff8cfdd79a781bf493dc426bb059916debbb98c1b7c20a9d0f24a5f7; C2 URL/IP: 173.249.50.34-shareboxs.net). The report provides manifest and permissions details, code excerpts showing data collection and socket-based exfiltration, command handlers, and contextual analysis indicating targeted surveillance of Baloch users with possible state actor involvement; recommended mitigations and IOCs are included.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
