"🔥 CapraTube Alert! Transparent Tribe's Sneaky Move 📺📲"
Transparent Tribe, a suspected Pakistani actor, has unveiled CapraTube, a deceptive Android application that mimics YouTube. SentinelLabs discovered three Android application packages (APKs) linked to Transparent Tribe's CapraRAT mobile remote access trojan (RAT). These apps give the illusion of being YouTube but are far less feature-rich than the genuine Android YouTube app.
CapraRAT is a potent tool, granting attackers control over vast amounts of data on infected Android devices. This RAT has been used for surveillance against targets related to the disputed Kashmir region and human rights activists focusing on Pakistan. The group distributes these Android apps outside the Google Play Store, using self-hosted websites and social engineering to lure users into installing weaponized applications.
In 2023, the group spread CapraRAT Android apps disguised as a dating service that carried out spyware activities. One of the newly identified APKs connects to a YouTube channel owned by Piya Sharma, suggesting the actor continues to employ romance-based social engineering tactics.
Key features of CapraRAT include:
- Recording via microphone, front & rear cameras 🎥
- Collecting SMS, multimedia message contents, call logs 📞
- Sending SMS messages, blocking incoming SMS 📩
- Initiating phone calls 📲
- Taking screen captures 🖼️
- Overriding system settings like GPS & Network 🛰️
- Modifying files on the phone's filesystem 📁
For those in the India and Pakistan regions linked to diplomatic, military, or activist matters, it's crucial to be cautious of this actor and threat. Always be wary of apps outside the Google Play store and evaluate the permissions they request.
Source: SentinelOne Labs
Tags: #CapraTube #TransparentTribe #CapraRAT #CyberSecurity #AndroidMalware #SentinelLabs #MobileSecurity #APT 🌐🔐📱
Author: Alex Delamotte.