Booby-Trapped Messaging Apps Used for Spying: Researchers

Advertisement
By Agence France-Presse | Updated: 19 January 2018 12:55 IST

An espionage campaign using malware-infected messaging apps has been stealing smartphone data from activists, soldiers, lawyers, journalists and others in more than 20 countries, researchers said in a report Thursday.

A report authored by digital rights group Electronic Frontier Foundation and mobile security firm Lookout detailed discovery of "a prolific actor" with nation-state capabilities "exploiting targets globally across multiple platforms."

Desktop computers were also targeted, but getting into data-rich mobile devices was a primary objective, according to the report.

Advertisement

With fake versions of secure messaging services like WhatsApp and Signal, the scheme has enabled attackers to take pictures, capture audio, pinpoint locations, and mine handsets for private data.

Advertisement

EFF and Lookout researchers dubbed the threat "Dark Caracal."

People in the US, Canada, Germany, Lebanon, and France have been hit by Dark Caracal, according to EFF director of cybersecurity Eva Galperin.

Advertisement

"This is a very large, global campaign, focused on mobile devices," Galperin said.

"Mobile is the future of spying, because phones are full of so much data about a person's day-to-day life."

Advertisement

Hundreds of gigabytes of data have been taken from thousands of victims in more than 21 countries, according to Lookout and the EFF.

There were indications that Dark Caracal might be an infrastructure hosting a number of widespread, global cyberespionage campaigns, some of which date back years, the report said.

Because the apps fool people into thinking they are legitimate, users give them access to cameras, microphones and data.

"All Dark Caracal needed was application permissions that users themselves granted when they downloaded the apps, not realizing that they contained malware," said EFF staff technologist Cooper Quintin.

"This research shows it's not difficult to create a strategy allowing people and governments spy to on targets around the world."

Researchers reported that they tracked Dark Caracal to a building in Beirut belonging to the Lebanese General Security Directorate.

Analysis showed that devices of military personnel, businesses, journalists, lawyers, educators, and medical professionals have been compromised, according to the report.

"Not only was Dark Caracal able to cast its net wide, it was also able to gain deep insight into each of the victim's lives," the report concluded.

Cyber-security professionals consistently warn people to be wary when downloading software, avoiding programs shared through links or email and instead relying on trusted sources.

 

Get your daily dose of tech news, reviews, and insights, in under 80 characters on Gadgets 360 Turbo. Connect with fellow tech lovers on our Forum. Follow us on X, Facebook, WhatsApp, Threads and Google News for instant updates. Catch all the action on our YouTube channel.

Further reading: Apps, Social, Mobiles
Advertisement

Related Stories

Popular Mobile Brands
  1. Oppo Reno 15 Series 5G Confirmed to Launch in India Soon
  2. Oppo Reno 15 Pro Mini Confirmed to Launch in India Alongside These Models
  3. iQOO Z11 Turbo Design Teased; Specifications Leaked
  4. OnePlus 15R Goes on Sale in India For the First Time Today: Price, Offers
  5. Oppo Find X9 Ultra Camera Specifications Leaked Ahead of China Launch
  6. Here's When the Samsung Galaxy S26 Series Could Reach Stores in 2026
  7. Xiaomi 17 Ultra to Launch in a 'Starry' Green Shade in China on This Date
  8. Xiaomi Watch 5, Xiaomi Buds 6 to Launch Alongside Xiaomi 17 Ultra
  9. OnePlus Turbo Visits Geekbench With This Snapdragon Chipset
  10. Poco M8 Series India Launch Teased, Poco M8 and M8 Pro Could Debut
  1. A Knight of the Seven Kingdoms OTT Release: Know When and Where to Watch This Prequel of Game of Thrones
  2. Nobody 2 Now Streaming Online: Know Everything About This American Action Thriller Film
  3. Osiris Now Streaming on JioHotstar: Everything You Need to Know
  4. Revolver Rita OTT Release Date Revealed: Know Everything About Streaming, Plot, Cast, and More
  5. ChatGPT Agreeing With Users is Dangerous, Says Lawyer in Murder-Suicide Case: Report
  6. CES 2026: Samsung to Expand Bespoke Appliances With Improved AI Vision, Google Gemini AI
  7. Redmi Pad 2 Pro 5G India Launch Date Announced; Teaser Confirms 12,000mAh Battery
  8. Oppo Reno 15 Pro Mini Confirmed to Launch in India Along With Reno 15, Reno 15 Pro; Flipkart Availability Announced
  9. Instagram Could Embrace Long-Form Video, Premium Content to Compete With TikTok, Says Adam Mosseri
  10. Samsung 'Wide Fold’ Will Reportedly Compete With Apple’s First Foldable iPhone in 2026
Gadgets 360 is available in
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2025. All rights reserved.