TECHNOLOGY
Kaspersky Lab researchers have discovered ZooPark, a sophisticated cyberespionage campaign, which, for several years, has been targeting users of Android devices based in several middle-eastern countries.
Kaspersky Lab researchers have discovered ZooPark, a sophisticated cyberespionage campaign, which, for several years, has been targeting users of Android devices based in several middle-eastern countries.
Using legitimate websites as sources of infection, the campaign appears to be a nation-state backed operation aimed at political organisations, activists and other targets based in the region. Recently, Kaspersky Lab researchers received something that seemed to be a sample of unknown Android-malware. At first glance, the malware appeared to be nothing serious: a technically very simple and straight-forward cyberespionage tool.
Researchers decided to investigate further and soon discovered a far more recent and sophisticated version of the same app. They decided to call it ZooPark. Some of the malicious ZooPark apps are being distributed from news and political websites popular in specific parts of the middle east.
They are disguised as legitimate apps with names like 'TelegramGroups' and Alnaharegypt news among others, recognised in and relevant to some middle eastern countries. Upon successful infection, the malware provides the attacker with the following abilities:
Exfiltration:
Contacts
Account data
Call logs and audio recordings of the calls
Pictures stored on the SD card of the device
GPS location
SMS messages
Installed application details, browser data
Keylogs and clipboard data
Etc.
Backdoor functionality:
Silently sending SMS
Silently making calls
Execution of shell commands
An additional malicious function targets instant messaging applications, like Telegram, WhatsApp IMO; the web browser (Chrome) and some other applications. It allows the malware to steal the internal databases of the attacked apps. For example, with the web browser, this would mean that stored credentials to other websites could be compromised as a result of the attack. The investigation suggests that the attackers are focusing on users based in Egypt, Jordan, Morocco, Lebanon and Iran.
Based on the news topics that the attackers used to lure victims into installing the malware, members of the United Nations Relief and Works Agency are among the possible targets of the ZooPark malware. "More and more people use their mobile devices as their primary or sometimes even only communication device. And that is certainly being spotted by nation-state sponsored actors, who are building their toolsets so they will be efficient enough to track mobile users. The ZooPark APT, actively spying on targets in middle eastern countries, is one such example, but it is certainly not the only one," said Alexey Firsh, a security expert at Kaspersky Lab.
In total, Kaspersky Lab researchers were able to identify at least four generations of the espionage malware related to the ZooPark family, which has been active since at least 2015. Kaspersky Lab products successfully detect and block this threat.
Oreshnik Hypersonic Missile: Which nations are within its range?
'I have faced a lot of...': Arjun Kapoor REVEALS his biggest fear amid break up with Malaika Arora
How millions of Indians may get affected due to US indictment of Gautam Adani in bribery case
Amid divorce rumours with Aishwarya Rai, Abhishek Bachchan says 'missing someone is okay but...'
After Bibles, watches and sneakers, Donald Trump is now selling autographed guitars, price is...
Delhi pollution: Air quality improves to ‘very poor’ category, AQI at...
Vladimir Putin's BIG threat, warns he could strike UK with new ballistic missile if...
Shillong Teer Results TODAY November 22, 2024 Live Updates: Check winning numbers here
Somebody misbehaved with Alia Bhatt on Highway sets then Imtiaz Ali had to...
Zomato CEO Deepinder Goyal reveals twist behind Rs 200000 job fee, closes application window
Days after Ratan Tata's demise, Tata Group's Rs 131000 crore company inks pact with ADB for...
WATCH: Woman makes Biryani with Parle-G biscuits, viral video fumes internet
Only train in India in which passengers can travel for FREE; check route, timings and more
'Justice for biryani': Parle-G biryani takes internet by storm, video goes viral
DNA TV Show: Why Gautam Adani charged with bribery and fraud in US
IND vs AUS: Records Virat Kohli can break during Border-Gavaskar Trophy
Diljit Dosanjh fans get angry over Ananya Panday's birthday post for her grandmother, here's why
Reddit suffers outage with ‘upstream connect error’ message, says 'currently investigating...'
Border-Gavaskar Trophy: How has Jasprit Bumrah fared in Tests in Australia?
Delhi records coldest night of the season, temp drops to...
Crossing the Line: Ukraine's Use of Storm Shadow Missiles and the Escalation of Conflict
When Malaika Arora talked about the controversial ‘instant pleasure’ ad, it was for…
This is the world’s most expensive shopping street, not Fifth Avenue, New Bond Street, it is...
Big setback for Gautam Adani, Kenya cancels Rs 6216 crore deal with Adani Group due to...
Viral video: Man’s jugaad to stay warm in winter will leave you SHOCKED, watch here
Hinduja Group firm gets key approval for acquisition of Anil Ambani's debt-ridden Reliance Capital
Viral video: Middle-Class man lives dream of having tea at Taj Hotel, netizens applauds
Shloka Mehta looks stunning in white floral kurta as she clicked with Akash Ambani, it costs Rs....
Who is Sagar Adani, Gautam Adani's nephew, accused of bribery, fraud charges in US?
PayPal down: Several users face issue while logging into accounts, say 'no one could...'
IND vs AUS: Jasprit Bumrah, Pat Cummins eye historic captaincy milestone in Perth Test
BGT 2024, Ind vs Aus: Can Shubhman Gill be the new Cheteshwar Pujara? Is he really ready?
The Ultimate Guide to Luxury Gifting: Discover Heirloom Pashmina by Pashmina.com
Effortless Relocations: The Perks Of Professional Removalists In Melbourne
Watch: Pakistan fan with 'Imran Khan' poster asked to leave Hobart stadium in Australia
International Criminal Court issues arrest warrant against Israeli PM Benjamin Netanyahu for...
What is demisexuality? Everything you need to know about this lesser-known sexual orientation
WATCH: World’s shortest woman meets world’s tallest woman, video goes viral
IND vs AUS 1st Test: Predicted playing XIs, Perth weather forecast and pitch report
IND vs AUS: When will Rohit Sharma join India squad? Check latest update
'Scam 2024': Diljit Dosanjh lookalike pranks people on Pune streets, video goes viral
Delhi Air Pollution: Centre announces staggered work timings for govt employees; check details
Mukesh Ambani's Reliance Jio loses nearly 80 lakh subscribers in just 30 days, BSNL adds...
IND vs AUS, 1st Test Dream11 prediction: Fantasy cricket tips for India vs Australia match
This country has most expensive passport in world, not US, UK, UAE, it costs Rs...
Amitabh Bachchan opens up on Aishwarya Rai-Abhishek Bachchan divorce rumours
Amid rising air pollution, Delhi-NCR's crematorium records cleanest air; check AQI here
Revolutionising Medical Imaging: Venudhar Rao Hajari’s impact on healthcare technology
Abhishek Gupta and Onevision Media: Scaling brands on social media
Video shows Korean girl eating jalebi for first time, her reaction to Indian sweet goes viral
Cristiano Ronaldo confirms THIS YouTube star as his next guest, says, 'Will break Internet'
Delhi Assembly Elections: AAP releases first list of 11 candidates for 2025 polls
Adani Group's FIRST REACTION after US indicts Gautam Adani in alleged bribery case
Instagram introduces new feature, know how to reset app's algorithm, change your feed
No mention of Aaradhya Bachchan in Amitabh Bachchan's post on birthdays, it happened recently
Oppo Find X8 and X8 Pro launched in India, check specifications, price, other details
Charges against Gautam Adani: BJP's scathing attack on Congress, questions timing of development
Jasprit Bumrah's BIG statement on taking up Perth test captaincy, says, 'tactically better...'
Blackout on breaks: Company imposes no-sick-leave policy until 2025
Drug-laden terrorists on India's western, northern frontiers
Mohammad Shami trolls Sanjay Manjrekar over IPL auction bid prediction, says, 'Baba ki...'