Photo Portraying Google Play Store Icon on Android Phone
© PixieMe/Shutterstock.com
No AI-generated content: this article is written and researched by humans
Table of contents

Threat actors are circulating spyware disguised as a chat app named SafeChat. The malicious app, which is being spread via WhatsApp, is designed to capture various data, including keystrokes and on-screen activity, CYFIRMA threat hunters revealed in a report on Friday.

SafeChat also collects personal data such as users’ location, SMS, contacts, call logs, GPS data, and storage. The app is designed to interact with other installed chat applications and exploits permissions for malicious purposes.

This spyware campaign, attributed to the India-based Advanced Persistent Threat (APT) group Bahamut, mainly targets individuals in South Asia. CYFIRMA researchers believe the spyware at the core of SafeChat is a variation of Coverlm.

“This particular malware exhibits a similar operational mechanism to the previously identified malware (distributed through the Google Play Store by the notorious APT group known as ‘DoNot’), however, this malware has more permissions, and thus presents a higher level of threat,” the researchers explained in their report.

SafeChat’s ‘Dangerous’ Permission Requests

According to CYFIRMA, SafeChat is being spread via spear phishing messages on WhatsApp. On the surface, the SafeChat app seems legitimate — it claims to be a “secure chatting app” and has similar features to other chat apps.

The biggest red flag is its “dangerous” permission requests. Upon installation, the app requests permission to keep working in the background and ignore battery optimization.

“Once allowed, the app will work even when the app is minimized or closed. This permission will let command and control seamlessly communicate with the app,” CYFIRMA researchers said.

SafeChat also requires further permissions to work properly. If users approve the request, the app can capture their keystrokes and other on-screen activity. It also accesses specific directories and data on the device. If users don’t approve the request, the app repeatedly asks for permission.

“The user interface of this app successfully deceives users into believing its authenticity, allowing the threat actor to extract all the necessary information, before the victim realizes that the app is a dummy, the malware cleverly exploits unsuspecting Android Libraries to extract and transmit data to a command-and-control server,” the researchers said.

Protecting Your Device From Trojanized Apps

This isn’t the first time the Bahamut APT group has been discovered using a trojanized app to spread malware. In 2022, ESET cybersecurity researchers found the group using a fake VPN app named SecureVPN to spread spyware and access sensitive data on targeted devices.

According to CYFIRMA, Bahamut’s actions serve the interests of a “nation-state government.”

“While some security organizations initially identified the threat as originating from a mercenary group, our own analysis indicates that it is, in fact, an Indian APT group acting on behalf of one nation-state government,” the CYFIRMA team said.

To stay safe from trojanized apps, it’s important to only install apps from trusted sources like the Google Play Store. Even then, the Play Store has been known to host malicious apps, so read about any app before you install it and ensure the developer is legitimate. Also, be wary of apps that require extensive permissions and use antivirus software that provides real-time protection to detect and block malicious apps.

If you suspect an app on your device may be malware, consult our Android malware removal guide to learn how to detect and remove it from your device.

Follow us on Twitter, Threads, and Mastodon for more news!

Leave a comment