Booby-Trapped Messaging Apps Used for Spying: Researchers

Advertisement
By Agence France-Presse | Updated: 19 January 2018 12:55 IST

An espionage campaign using malware-infected messaging apps has been stealing smartphone data from activists, soldiers, lawyers, journalists and others in more than 20 countries, researchers said in a report Thursday.

A report authored by digital rights group Electronic Frontier Foundation and mobile security firm Lookout detailed discovery of "a prolific actor" with nation-state capabilities "exploiting targets globally across multiple platforms."

Desktop computers were also targeted, but getting into data-rich mobile devices was a primary objective, according to the report.

Advertisement

With fake versions of secure messaging services like WhatsApp and Signal, the scheme has enabled attackers to take pictures, capture audio, pinpoint locations, and mine handsets for private data.

Advertisement

EFF and Lookout researchers dubbed the threat "Dark Caracal."

People in the US, Canada, Germany, Lebanon, and France have been hit by Dark Caracal, according to EFF director of cybersecurity Eva Galperin.

Advertisement

"This is a very large, global campaign, focused on mobile devices," Galperin said.

"Mobile is the future of spying, because phones are full of so much data about a person's day-to-day life."

Advertisement

Hundreds of gigabytes of data have been taken from thousands of victims in more than 21 countries, according to Lookout and the EFF.

There were indications that Dark Caracal might be an infrastructure hosting a number of widespread, global cyberespionage campaigns, some of which date back years, the report said.

Because the apps fool people into thinking they are legitimate, users give them access to cameras, microphones and data.

"All Dark Caracal needed was application permissions that users themselves granted when they downloaded the apps, not realizing that they contained malware," said EFF staff technologist Cooper Quintin.

"This research shows it's not difficult to create a strategy allowing people and governments spy to on targets around the world."

Researchers reported that they tracked Dark Caracal to a building in Beirut belonging to the Lebanese General Security Directorate.

Analysis showed that devices of military personnel, businesses, journalists, lawyers, educators, and medical professionals have been compromised, according to the report.

"Not only was Dark Caracal able to cast its net wide, it was also able to gain deep insight into each of the victim's lives," the report concluded.

Cyber-security professionals consistently warn people to be wary when downloading software, avoiding programs shared through links or email and instead relying on trusted sources.

 

For details of the latest launches and news from Samsung, Xiaomi, Realme, OnePlus, Oppo and other companies at the Mobile World Congress in Barcelona, visit our MWC 2025 hub.

Further reading: Apps, Social, Mobiles
Advertisement

Related Stories

Popular Mobile Brands
  1. Motorola Edge 70 Fusion Launched in India With 50-Megapixel Sony LYT-710 Camera
  2. Nothing Phone 4a, Phone 4a Pro Launched in India at This Price
  3. Realme C83 5G Debuts in India With a 7,000mAh Battery at This Price
  4. Nothing Phone 4a vs Motorola Edge 70: Price in India, Features Compared
  5. Microsoft Says 'Project Helix' Next-Gen Xbox Will Offer PC, Console Gaming
  6. Nothing Phone 4a First Impressions
  7. Vivo T5x 5G AnTuTu Score Exceeds 1 Million Points, Will Launch in India Soon
  8. The OnePlus 15T is expected to go official in China soon as the latest addition to the One
  9. OpenAI's GPT-5.4 AI Model Is Here, and It Can Use Your Computer
  10. Nothing Phone 4a vs Phone 3a: Price in India, Specifications Compared
  1. Oppo Find N6 IP Rating Confirmed as Leaked Renders Reveal Design; Oppo Watch X3 Teased Officially
  2. Realme C83 5G Launched in India With 7,000mAh Battery, 13-Megapixel Camera: Price, Specifications
  3. Microsoft Gaming CEO Asha Sharma Confirms ‘Project Helix’ Next-Gen Hybrid Xbox That Plays PC, Console Games
  4. OpenAI Releases GPT-5.4 AI Models With Agentic Computer-Use Capabilities
  5. Motorola Edge 70 Fusion Launched in India With 50-Megapixel Sony LYT-710 Camera, 7,000mAh Battery
  6. MacBook Pro (2026) With the M5 Max Chip Outpaces Older MacBook Pro Model With M4 Max on Geekbench
  7. Samsung Galaxy Smartphone Prices Reportedly Hiked in India; Several Models Said to Be Affected
  8. Honor X80i Spotted on TENAA With 6,800mAh Battery, 6.6-Inch OLED Display
  9. OnePlus 15T Tipped to Feature 1.5K 165Hz Display as Company Confirms Key Specifications
  10. Samsung Galaxy A37 5G and Galaxy A57 5G Specifications Reportedly Leaked in Full Ahead of Launch
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2026. All rights reserved.