Spyware maker caught distributing malicious Android apps for years


Italian spyware maker SIO, known to sell its products to government customers, is behind a series of malicious Android apps that masquerade as WhatsApp and other popular apps but steal private data from a target’s device, TechCrunch has exclusively learned.

Late last year, a security researcher shared three Android apps with TechCrunch, claiming they were likely government spyware used in Italy against unknown victims. TechCrunch asked Google and mobile security firm Lookout to analyze the apps, and both confirmed that the apps were spyware.

Read more…
Source: TechCrunch News


Sign up for our Newsletter


Related:

  • Witchetty: Group Uses Updated Toolset in Attacks on Governments in Middle East

    September 29, 2022

    The Witchetty espionage group (aka LookingFrog) has been progressively updating its toolset, using new malware in attacks on targets in the Middle East and Africa. Among the new tools being used by the group is a backdoor Trojan (Backdoor.Stegmap) that employs steganography, a rarely seen technique where malicious code is hidden within an image. In attacks ...

  • Greece wiretap and spyware claims circle around PM Mitsotakis

    September 8, 2022

    It has been dubbed the Greek Watergate. What began as a surveillance of a little-known journalist in Greece has evolved into an array of revelations circling around the Greek government. The story emerged last spring, when Thanasis Koukakis found out his phone had been infected with spyware that can extract data from a device. He also ...

  • British judge rules dissident can sue Saudi Arabia for Pegasus hacking

    August 19, 2022

    A British judge has ruled that a case against the kingdom of Saudi Arabia brought by a dissident satirist who was targeted with spyware can proceed, a decision that has been hailed as precedent-setting and one that could allow other hacking victims in Britain to sue foreign governments who order such attacks. The case against Saudi ...

  • Apple introduces Lockdown Mode to protect iPhones from state-sponsored hacking

    July 6, 2022

    Apple announced a new feature for iPhones called Lockdown Mode on Wednesday to protect high-profile users such as politicians and activists against state-sponsored hackers. Lockdown Mode turns off several features on the iPhone in order to make it less vulnerable to spyware by significantly reducing the number of features that attackers can access and potentially hack. Specifically, ...

  • Spyware vendor targets users in Italy and Kazakhstan

    June 23, 2022

    Google has been tracking the activities of commercial spyware vendors for years, and taking steps to protect people. Just last week, Google testified at the EU Parliamentary hearing on “Big Tech and Spyware” about the work we have done to monitor and disrupt this thriving industry. Seven of the nine zero-day vulnerabilities our Threat Analysis Group ...

  • Takedown of SMS-based FluBot spyware infecting Android phones

    June 1, 2022

    An international law enforcement operation involving 11 countries has resulted in the takedown of one of the fastest-spreading mobile malware to date. Known as FluBot, this Android malware has been spreading aggressively through SMS, stealing passwords, online banking details and other sensitive information from infected smartphones across the world. Its infrastructure was successfully disrupted earlier ...