Home Malware Programs Malware CallerSpy

CallerSpy

Posted: December 4, 2019

CallerSpy is an espionage tool available for Android devices. It is not clear if a high-profile threat actor is related to the development of this malware. Still, malware researchers were able to identify the fraudulent schemes used to distribute this threatening application – it poses as an Android chat application that goes by the name Chatrious or Apex App. One of the websites hosting the fake chat application was disguised to look like a legitimate Google page, and it even used a similar domain name, 'Gooogle(dot)press.' Some users might not notice the extra 'o' symbol in the domain name, and they may think that they will be downloading a legitimate application provided by Google.

The purpose of CallerSpy is to gain persistence on the infected Android device and then proceed to perform reconnaissance and espionage operations over a long period. It is not clear whether the malware is used to target a specific region, and it is possible that authors of the CallerSpy malware may be going after random targets, hoping that they would strike lucky and get their hands on valuable information.

CallerSpy Engages in Spyware Activities

Once the CallerSpy spyware is deployed, it will load its espionage modules that enable its operator to carry out various tasks immediately:

  • Collect call logs.
  • Collec the contact list.
  • Read and manage text messages.
  • Record audio via the phone or tablet's microphone.
  • Take screenshots.
  • Browse and collect files.

The attackers control the CallerSpy malware via a remote Command & Control server that transmits commands to the infected device. The crooks can then extract the collected data to their control server periodically.

One of the most concerning sides of the bogus pages that the crooks use to distribute the CallerSpy malware is that they also claim to offer iOS and Windows variants in the future – this might be a social engineering trick to make the websites seem more believable, or it might mean that the threat actor is planning on releasing Windows and iOS variants of the CallerSpy malware.

Protecting your Android device from threats like CallerSpy requires several, but simple security measures. Start by installing a reputable anti-virus application, and then try to follow the best security practices when browsing the Web – stay away from dubious pages, and never download non-trustworthy software.

Loading...