Researchers have discovered an updated version of the notorious GravityRAT spyware in two dodgy messaging apps. The latest iteration of this spyware can steal WhatsApp backups and receive commands to delete files on targeted devices.
On Thursday, Slovakia-based cybersecurity firm ESET said the random access trojan spyware has been circulated via two apps — namely BingeChat and Chatico — since 2022, potentially giving threat actors access to sensitive data on compromised devices.
The trojanized apps weren’t uploaded to Google Play Store. Instead, they were distributed via websites. When ESET researchers tried to sign up on the site and download BingeChat, they were required to log in, indicating that “potential victims are highly targeted.”
“It is most probable that the operators only open registration when they expect a specific victim to visit, possibly with a particular IP address, geolocation, custom URL, or within a specific timeframe,” ESET researchers explained in a blog post.
GravityRAT has been on the radar of cybersecurity researchers since at least 2015 and has been used to target victims in India. The threat actors behind this spyware remain unknown, although they’re suspected to be based in Pakistan.
How GravityRAT Works
BingeChat and Chatico, the two apps used to spread GravityRAT, “provide legitimate chat functionality” using the OMEMO Instant Messenger code. This increases the likelihood that potential victims won’t know they contain spyware.
Once installed, GravityRAT can access and extract WhatsApp backups, media files, SMS messages, contact lists, call logs, and location data. Its ability to target WhatsApp backups is particularly alarming, as it opens up sensitive personal and business communications to cybercriminals, potentially leading to identity theft, financial fraud, and corporate espionage.
The malware can also collect system information, such as the device’s model, manufacturer, system version, and installed applications. The attackers can use this information to refine their attacks and exploit specific vulnerabilities.
The website and the command-and-control server used to distribute Chatico are now offline. However, the BingeChat campaign is still ongoing.
Protecting Your Device From Malicious Apps
We recommend exercising caution when downloading apps; only download apps only from trusted sources, such as the Google Play Store, and read about the developer of any app you choose to get. You’ll find more tips in our comprehensive guide to staying safe online.
If you suspect you may have a malicious app on your device, read our Android malware removal guide for instructions on how to identify and get rid of it.
Subscribe to our newsletter or follow us on Twitter to receive updates about the latest news and developments in online privacy and security.
