ESET, a company specializing in proactive threat detection, has announced the discovery of a sophisticated espionage campaign targeting Android users. The campaign uses a malicious application called GhostChat.
The application presents itself as a romantic dating service, allowing victims to interact with female profiles that, upon technical investigation, turned out to be fake accounts managed through WhatsApp. The purpose is to conduct covert and continuous surveillance.
After installation, the application prompts users to enter unlock codes, which are predefined in the application's code. Upon entering these codes, the victim is redirected to a real WhatsApp conversation operated by the attackers.
The real danger lies in its background functions: the malicious GhostChat code activates even before the user logs in. Additionally, it includes a scheduled task that scans for new documents on the device every five minutes, ensuring a constant flow of private information to the attackers.