Kaspersky warns of spyware-loaded VPN ‘SandStrike’ campaign to attack Baháʼí community

On an associated Telegram channel, the SandStrike perpetrator shared a VPN application that had fully-functioning spyware

November 05, 2022 11:49 am | Updated 11:49 am IST

Kaspersky warns of spyware-loaded VPN ‘SandStrike’ campaign to attack Baháʼí community

Kaspersky warns of spyware-loaded VPN ‘SandStrike’ campaign to attack Baháʼí community | Photo Credit: REUTERS

Cybersecurity company Kaspersky reported on Friday that members of the Baháʼí religious community were being targeted by the Android espionage campaign SandStrike, in which a VPN application with spyware was shared with victims.

(For insights on emerging themes at the intersection of technology, business and policy, subscribe to our tech newsletter Today’s Cache.)

Calling the spyware “highly sophisticated,” Kaspersky reported that the hackers started Facebook and Instagram accounts with over 1,000 followers and shared religious content to attract more followers of the Baháʼí faith.

On an associated Telegram channel, the SandStrike perpetrator shared a VPN application that had fully-functioning spyware. Through this, the attacker would have been able to exploit data such as the users’ call logs and contact lists.

Followers of the Bahá’í faith are targeted and persecuted in several countries, as many orthodox leaders and regimes believe the religion violates the principles of Islam.

“In this channel, the actor behind SandStrike distributed a seemingly harmless VPN application to access sites banned in certain regions, for example, religious-related materials. To make this application fully functional, adversaries also set up their own VPN infrastructure,” said Kaspersky’s report.

The spyware-loaded VPN would have let the attacker further track the users to learn more about their lives.

The Bahá’í faith originated in Iran in the 19th century and has millions of followers worldwide.

Top News Today

Sign in to unlock member-only benefits!
  • Access 10 free stories every month
  • Save stories to read later
  • Access to comment on every story
  • Sign-up/manage your newsletter subscriptions with a single click
  • Get notified by email for early access to discounts & offers on our products
Sign in

Comments

Comments have to be in English, and in full sentences. They cannot be abusive or personal. Please abide by our community guidelines for posting your comments.

We have migrated to a new commenting platform. If you are already a registered user of The Hindu and logged in, you may continue to engage with our articles. If you do not have an account please register and login to post comments. Users can access their older comments by logging into their accounts on Vuukle.