CapraTube Remix: Spyware Android, care vizează jucătorii și entuziaștii de arme - TECHNEWSRO

Cercetătorii de la SentinelLabs au identificat o nouă variantă a spyware-ului Transparent Tribes pentru Android, denumită CapraTube. Acest malware vizează jucătorii și entuziaștii de arme, folosindu-se de interesele lor pentru a infecta dispozitivele și a fura informații sensibile.ContextTransparent Tribes este o familie de spyware pentru Android bine cunoscută, activă din 2017. Este utilizată în principal

TECHNEWSRO - Pasionat de tehnologie

"🔥 CapraTube Alert! Transparent Tribe's Sneaky Move 📺📲"

Transparent Tribe, a suspected Pakistani actor, has unveiled CapraTube, a deceptive Android application that mimics YouTube. SentinelLabs discovered three Android application packages (APKs) linked to Transparent Tribe's CapraRAT mobile remote access trojan (RAT). These apps give the illusion of being YouTube but are far less feature-rich than the genuine Android YouTube app.

CapraRAT is a potent tool, granting attackers control over vast amounts of data on infected Android devices. This RAT has been used for surveillance against targets related to the disputed Kashmir region and human rights activists focusing on Pakistan. The group distributes these Android apps outside the Google Play Store, using self-hosted websites and social engineering to lure users into installing weaponized applications.

In 2023, the group spread CapraRAT Android apps disguised as a dating service that carried out spyware activities. One of the newly identified APKs connects to a YouTube channel owned by Piya Sharma, suggesting the actor continues to employ romance-based social engineering tactics.

Key features of CapraRAT include:

  • Recording via microphone, front & rear cameras 🎥
  • Collecting SMS, multimedia message contents, call logs 📞
  • Sending SMS messages, blocking incoming SMS 📩
  • Initiating phone calls 📲
  • Taking screen captures 🖼️
  • Overriding system settings like GPS & Network 🛰️
  • Modifying files on the phone's filesystem 📁

For those in the India and Pakistan regions linked to diplomatic, military, or activist matters, it's crucial to be cautious of this actor and threat. Always be wary of apps outside the Google Play store and evaluate the permissions they request.

Source: SentinelOne Labs

Tags: #CapraTube #TransparentTribe #CapraRAT #CyberSecurity #AndroidMalware #SentinelLabs #MobileSecurity #APT 🌐🔐📱

Author: Alex Delamotte.

CapraTube | Transparent Tribe’s CapraRAT Mimics YouTube to Hijack Android Phones

Pakistan-aligned threat actor weaponizes fake YouTube apps on the Android platform to deliver mobile remote access trojan spyware.

SentinelOne