Sophisticated Android Spyware Attack Found Targeting Users in India: Kaspersky

This “PhantomLance” campaign included multiple versions of a complex spyware to target users in India, Vietnam, Bangladesh, and Indonesia.

Advertisement
By Tasneem Akolawala | Updated: 29 April 2020 15:18 IST
Highlights
  • PhantomLance campaign may have been started by OceanLotus
  • The main aim of this campaign was to gather data
  • Kaspersky observed 300 infection attempts since 2016

Spy apps were distributed on various platforms like Google Play and APKpure

Research firm Kaspersky has discovered a new spy campaign that has been stealing data off of hundreds of users for the last five years. Dubbed as PhantomLance, this campaign has been active since 2015, and may have been started by hacker group OceanLotus. This campaign includes multiple versions of a complex spyware to target users in India, Vietnam, Bangladesh, and Indonesia. The main purpose of this spyware was to gather information, and Kaspersky observed 300 infection attempts since 2016. The campaign includes a set of malicious apps that were not interested in mass installation, and their main aim was to spy on select users. This hints at how hackers are resorting to more sophisticated ways to become harder to find.

All the malicious spyware samples found by Kaspersky was reported to Google, and the tech giant has already delisted these apps from the Play Store. These apps posed to provide basic functionalities, but gathered information like list of installed applications, device information such as the model and OS version from the targeted device. ‘Furthermore, the malicious app was able to download and execute various malicious payloads, and thus adapt the payload that would be suitable to the specific device environment, such as the Android version and installed apps. This way, the actor was able to avoid overloading the application with unnecessary features and at the same time gather the desired information', Kaspersky notes.

PhantomLance was distributed on various platforms like Google Play and APKpure to make it seem more legitimate. The hacker group even created a fake developer account on GitHub for extra credibility. These apps managed to evade filtering mechanisms employed by Google and other app stores, by uploading first versions of the application without any malicious payloads. The apps received malicious payloads and a code to drop and execute these payloads via later updates. In Kaspersky's findings, Vietnam stood out as one of the top countries by number of attempted attacks. Some malicious apps used in the campaign were also made exclusively in Vietnamese.

Advertisement

Based on similarities in malicious code in past Android campaigns, Kaspersky researchers claim that the PhantomLance campaign was started by OceanLotus. While the apps have been taken down by Google from the Play Store, there is no guarantee that such apps would not crop up in the future. The research firm recommends investing in a viable security solution that protects the device from a wide range of threats. It is also recommended to install apps from Google Play Store with a lot of caution and evaluation. Check for reviews and ensure that apps from popular and credible developers are only downloaded on the phone.


Will OnePlus 8 series be able to take on iPhone SE (2020), Samsung Galaxy S20 in India? We discussed this on Orbital, our weekly technology podcast, which you can subscribe to via Apple Podcasts or RSS, download the episode, or just hit the play button below.

 

Get your daily dose of tech news, reviews, and insights, in under 80 characters on Gadgets 360 Turbo. Connect with fellow tech lovers on our Forum. Follow us on X, Facebook, WhatsApp, Threads and Google News for instant updates. Catch all the action on our YouTube channel.

Advertisement

Related Stories

Popular Mobile Brands
  1. Realme P4x 5G Launched in India With 7,000mAh Battery: See Price, Features
  2. Realme P4x 5G Launch Today: Know Price in India, Specs and More
  3. Motorola Edge 70 India Launch Date Leaked; Might Arrive With Bigger Battery
  4. OnePlus Ace 6T With Massive 8,300mAh Battery Launched at This Price
  5. Micron to Shut Down Crucial Amid Global RAM Shortage
  6. Apple Rolls Out iOS 26.2 RC Update for iPhone With These Fixes
  7. Pranav Mohanlal's Horror Thriller 'Dies Irae' Streams on OTT Soon
  8. Redmi 15C 5G First Impressions
  9. Apple Watch's Hypertension Notifications Feature Comes to India
  1. Bitcoin Price Consolidates Near $93,200 as Crypto Market Recovers From November Slowdown
  2. Realme P4x 5G Launched in India With MediaTek Dimensity 7400 Ultra SoC, 7,000mAh Battery: Price, Features
  3. iOS 26.2 Release Candidate Update Rolls Out to Beta Testers as Apple Prompts Users to Upgrade to iOS 26
  4. Amazon's Alexa+ AI Scene Search Feature Rolls Out to Prime Video on Fire TV: Here's How It Works
  5. Samsung Schedules 'The First Look' Event Two Days Ahead of CES 2026; Galaxy Z TriFold Global Launch Expected
  6. Micron Announces Exit from Consumer Business, to Shut Down Crucial Amid Global RAM Shortage
  7. Infinix Note 60 Ultra to Launch as Firm’s First Smartphone Designed by Pininfarina
  8. iPhone 17e Expected to Arrive With Thinner Bezels Alongside Dynamic Island: Report
  9. Apple Brings Hypertension Notifications Feature for Apple Watch to India: How to Use, Requirements, and More
  10. Samsung Galaxy Buds 4 Leak Hints at Smaller Battery; Galaxy Buds 4 Pro Could Get a Slight Upgrade
Gadgets 360 is available in
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2025. All rights reserved.