Threat actors use Israel-Hamas war to install spyware on Israeli Android users: Report

Threat actors are using a malicious version of the “RedAlert” rocket alert app to install spyware on Israeli Android users’ devices

Published - October 17, 2023 02:17 pm IST

Hackers of unknown origin were found leveraging the elevated interest in the “RedAlert” to distribute a malicious version of the app.

Hackers of unknown origin were found leveraging the elevated interest in the “RedAlert” to distribute a malicious version of the app. | Photo Credit: AP

Hackers of unknown origin and motivation were found leveraging the elevated interest in the “RedAlert”, an open-source app used by Israeli citizens to receive notifications of incoming rockets, to distribute a malicious version of the app.

The malicious version of the app, while offering the promised functionality, acts as spyware in the background, a report from Cloudflare said.

The app with the malicious code was found to collect sensitive user data including contacts, call logs, SMS, account information, as well as an overview of all installed apps from devices.

This malicious version was found to be distributed from the website “redalerts[.]me,” which was created on October 12, 2023. The website includes buttons to download the app for the iOS and Android platforms.

(For top technology news of the day, subscribe to our tech newsletter Today’s Cache)

While the iOS download button redirects users to the legitimate project’s page on the Apple App Store, the Android button directly downloads an APK file to be installed on the device.

The downloaded APK file uses the legitimate code of the RedAlert app, making it difficult for users to distinguish between the real and the malicious versions. The malicious app also contains anti-debugging, anti-emulation, and anti-test mechanisms that protect it from researchers and code-reviewing tools.

However, users can look at additional permissions the app requests upon installation. In case users notice the app asking for permission to access the information it does not require; they should uninstall the app and ensure they are using the latest app version that includes all available security fixes.

0 / 0
Sign in to unlock member-only benefits!
  • Access 10 free stories every month
  • Save stories to read later
  • Access to comment on every story
  • Sign-up/manage your newsletter subscriptions with a single click
  • Get notified by email for early access to discounts & offers on our products
Sign in

Comments

Comments have to be in English, and in full sentences. They cannot be abusive or personal. Please abide by our community guidelines for posting your comments.

We have migrated to a new commenting platform. If you are already a registered user of The Hindu and logged in, you may continue to engage with our articles. If you do not have an account please register and login to post comments. Users can access their older comments by logging into their accounts on Vuukle.