ViceLeaker Operation: mobile espionage targeting Middle East
#1
Exclamation 
Quote:
[Image: fanning-the-flames-viceleaker-operation-5.png]

In May 2018, we discovered a campaign targeting dozens of mobile Android devices belonging to Israeli citizens. Kaspersky spyware sensors caught the signal of an attack from the device of one of the victims; and a hash of the APK involved (Android application) was tagged in our sample feed for inspection. Once we looked into the file, we quickly found out that the inner-workings of the APK included a malicious payload, embedded in the original code of the application. This was an original spyware program, designed to exfiltrate almost all accessible information.

During the course of our research, we noticed that we were not the only ones to have found the operation. Researchers from Bitdefender also released an analysis of one of the samples in a blogpost. Although something had already been published, we decided to do something different with the data we acquired. The following month, we released a private report on our Threat Intelligence Portal to alert our clients about this newly discovered operation and began writing YARA rules in order to catch more samples. We decided to call the operation “ViceLeaker”, because of strings and variables in its code.

Mobile ViceLeaker

The following table shows meta information on the observed samples, including compiler timestamps:

MD5 Package Compiler C2
51df2597faa3fce38a4c5ae024f97b1c com.xapps.SexGameForAdults dexlib 2.x 188.165.28[.]251
2d108ff3a735dea1d1fdfa430f37fab2 com.psiphon3 dexlib 2.x 188.165.49[.]205
7ed754a802f0b6a1740a99683173db73 com.psiphon3 dexlib 2.x 188.165.49[.]205
3b89e5cd49c05ce6dc681589e6c368d9 ir.abed.dastan dexlib 2.x 185.141.60[.]213

To backdoor legitimate applications, attackers used a Smali injection technique – a type of injection that allows attackers to disassemble the code of original app with the Baksmali tool, add their malicious code, and assemble it with Smali. As a result, due to such an unusual compilation process, there were signs in the dex file that point to dexlib, a library used by the Smali tool to assemble dex files.
Continue Reading
[-] The following 2 users say Thank You to harlan4096 for this post:
  • dhruv2193, silversurfer
Reply


Forum Jump:


Users browsing this thread: 1 Guest(s)
[-]
Welcome
You have to register before you can post on our site.

Username/Email:


Password:





[-]
Recent Posts
Microsoft Defender Antivirus security in...
September-2025 (Pl...harlan4096 — 09:38
UltraSearch 4.8.4
Version 4.8.4 1...harlan4096 — 09:35
Brave 1.83.120
Release Channel 1....harlan4096 — 09:34
Meta launches new anti-scam tools for Wh...
Meta has announced...harlan4096 — 09:33
YouTube is adding an option to limit the...
YouTube is rolling...harlan4096 — 09:28

[-]
Birthdays
Today's Birthdays
avatar (38)Mblippek
Upcoming Birthdays
avatar (47)Michaelaceve
avatar (37)QuadirLigh
avatar (44)viecontAceve

[-]
Online Staff
There are no staff members currently online.

>