logo

Patchwork Using Romance Scam Lures to Infect Android Devices with VajraSpy Malware

ID: 21e908be-fa32-5a4f-b087-d9e980c8a41d

STIX ID: report--21e908be-fa32-5a4f-b087-d9e980c8a41d

Feed Name: The Hacker News

Threat Score
75/100

Date Published: 2024-02-05

Date Updated: 2026-04-24

Author: [email protected] (The Hacker News)

...
...

Patchwork—likely an India-linked threat actor—used romance-scam lures and malicious Android apps (VajraSpy/VajraRAT), some distributed via the Google Play Store, to target users in Pakistan and India; approximately 148 devices were estimated compromised, with apps capable of stealing contacts, files, call logs, SMS, and even WhatsApp/Signal messages, and of recording calls and taking pictures. Multiple package names (e.g., com.priv.talk, com.rafaqat.news) and a developer account (Mohammad Rizwan for Rafaqat) were identified, and the activity is linked to prior APT campaigns and broader regional extortion/malware trends.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.