Fake Dating App 'GhostChat' Used in Targeted Spyware Campaign in Pakistan
ESET researchers have uncovered a sophisticated Android spyware campaign targeting individuals in Pakistan using romance scam tactics. The malicious application, named GhostChat, disguises itself as a legitimate dating platform but functions primarily as a tool for mobile espionage. Upon installation, the app employs social engineering tricks, such as hardcoded passcodes for fake female profiles, to create an illusion of exclusive access. Its true purpose is to exfiltrate sensitive data and monitor device activity continuously. The investigation reveals that the same threat actor is conducting a broader surveillance operation, including ClickFix attacks on computers and exploiting WhatsApp's device-linking feature to access personal messages. These related attacks often use websites impersonating Pakistani governmental organizations as lures. GhostChat was not available on Google Play, requiring manual installation from unknown sources. ESET has shared findings with Google, and Android users are protected by Google Play Protect against known versions. While the campaign is focused on Pakistan, specific attribution to a threat actor remains unconfirmed due to insufficient evidence.
Wire timeline
Fake Dating App 'GhostChat' Used in Targeted Spyware Campaign in Pakistan
ESET researchers have uncovered a sophisticated Android spyware campaign targeting individuals in Pakistan using romance scam tactics. The malicious application, named GhostChat, disguises itself as a legitimate dating platform but functions primarily as a tool for mobile espionage. Upon installation, the app employs social engineering tricks, such as hardcoded passcodes for fake female profiles, to create an illusion of exclusive access. Its true purpose is to exfiltrate sensitive data and monitor device activity continuously. The investigation reveals that the same threat actor is conducting a broader surveillance operation, including ClickFix attacks on computers and exploiting WhatsApp's device-linking feature to access personal messages. These related attacks often use websites impersonating Pakistani governmental organizations as lures. GhostChat was not available on Google Play, requiring manual installation from unknown sources. ESET has shared findings with Google, and Android users are protected by Google Play Protect against known versions. While the campaign is focused on Pakistan, specific attribution to a threat actor remains unconfirmed due to insufficient evidence.
WeLiveSecurity