logo

'eXotic Visit' Spyware Campaign Targets Android Users in India and Pakistan

ID: 82e9c2ac-396e-50b2-9120-a28a21e69926

STIX ID: report--82e9c2ac-396e-50b2-9120-a28a21e69926

Feed Name: The Hacker News

Threat Score
70/100

Date Published: 2024-04-10

Date Updated: 2026-05-08

Author: [email protected] (The Hacker News)

...
...

ESET researchers uncovered an ongoing Android spyware campaign dubbed eXotic Visit targeting users in India and Pakistan since November 2021; malicious apps distributed via dedicated websites and Google Play (now removed) contained XploitSPY RAT functionality to harvest GPS, audio, contacts, messages, notifications, files and more, employing obfuscation, emulator detection and a native library to hide C2 details — the activity is being tracked as operated by a group named "Virtual Invaders" and has affected roughly 380 victims.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.