Ptechhub
  • News
  • Industries
    • Enterprise IT
    • AI & ML
    • Cybersecurity
    • Finance
    • Telco
  • Brand Hub
    • Lifesight
  • Blogs
No Result
View All Result
  • News
  • Industries
    • Enterprise IT
    • AI & ML
    • Cybersecurity
    • Finance
    • Telco
  • Brand Hub
    • Lifesight
  • Blogs
No Result
View All Result
PtechHub
No Result
View All Result

Android Spyware Disguised as Alpine Quest App Targets Russian Military Devices

The Hacker News by The Hacker News
April 23, 2025
Home Cybersecurity
Share on FacebookShare on Twitter


Apr 23, 2025Ravie LakshmananSpyware / Mobile Security

Cybersecurity researchers have revealed that Russian military personnel are the target of a new malicious campaign that distributes Android spyware under the guise of the Alpine Quest mapping software.

“The attackers hide this trojan inside modified Alpine Quest mapping software and distribute it in various ways, including through one of the Russian Android app catalogs,” Doctor Web said in an analysis.

The trojan has been found embedded in older versions of the software and propagated as a freely available variant of Alpine Quest Pro, a program with advanced functionality.

The Russian cybersecurity vendor said it also observed the malware, dubbed Android.Spy.1292.origin, being distributed in the form of an APK file via a fake Telegram channel.

Cybersecurity

While the threat actors initially provided a link for downloading the app in one of the Russian app catalogs through the Telegram channel, the trojanized version was later distributed directly as an APK as an app update.

What makes the attack campaign noteworthy is that it takes advantage of the fact that Alpine Quest is used by Russian military personnel in the Special Military Operation zone.

Once installed on an Android device, the malware-laced app looks and functions just like the original, allowing it to stay undetected for extended periods of time, while collecting sensitive data –

  • Mobile phone number and their accounts
  • Contact lists
  • Current date and geolocation
  • Information about stored files, and
  • App version

Besides sending the victim’s location every time it changes to a Telegram bot, the spyware supports the ability to download and run additional modules that allow it to exfiltrate files of interest, particularly those sent via Telegram and WhatsApp.

Android Spyware

“Android.Spy.1292.origin not only allows user locations to be monitored but also confidential files to be hijacked,” Doctor Web said. “In addition, its functionality can be expanded via the download of new modules, which allows it to then execute a wider spectrum of malicious tasks.”

To mitigate the risk posed by such threats, it’s advised to download Android apps only from trusted app marketplaces and avoid downloading “free” paid versions of software from dubious sources.

Russian Organizations Targeted by New Windows Backdoor

The disclosure comes as Kaspersky revealed that various large organizations in Russia, spanning the government, finance, and industrial sectors, have been targeted by a sophisticated backdoor by masquerading it as an update for a secure networking software called ViPNet.

Cybersecurity

“The backdoor targets computers connected to ViPNet networks,” the company said in a preliminary report. “The backdoor was distributed inside LZH archives with a structure typical of updates for the software product in question.”

Present within the archive is a malicious executable (“msinfo32.exe”) that acts as a loader for an encrypted payload also included in the file.

“The loader processes the contents of the file to load the backdoor into memory,” Kaspersky said. This backdoor is versatile: it can connect to a C2 server via TCP, allowing the attacker to steal files from infected computers and launch additional malicious components, among other things.”

Found this article interesting? Follow us on Twitter  and LinkedIn to read more exclusive content we post.





Source link

Tags: computer securitycyber attackscyber newscyber security newscyber security news todaycyber security updatescyber updatesdata breachhacker newshacking newshow to hackinformation securitynetwork securityransomware malwaresoftware vulnerabilitythe hacker news
The Hacker News

The Hacker News

Next Post
Stocks making the biggest moves premarket: Boeing, Tesla, BP, Eli Lilly and more

Stocks making the biggest moves premarket: Boeing, Tesla, BP, Eli Lilly and more

Recommended.

CHELSIO COMMUNICATIONS ANNOUNCES RESULTS OF T6 SMARTNIC TESTING WITH RED HAT® OPENSHIFT®

CHELSIO COMMUNICATIONS ANNOUNCES RESULTS OF T6 SMARTNIC TESTING WITH RED HAT® OPENSHIFT®

March 21, 2025
ADLINK’s Compact Box PC Wins Best-in-Show at Embedded World 2025

ADLINK’s Compact Box PC Wins Best-in-Show at Embedded World 2025

April 11, 2025

Trending.

⚡ Weekly Recap: Oracle 0-Day, BitLocker Bypass, VMScape, WhatsApp Worm & More

⚡ Weekly Recap: Oracle 0-Day, BitLocker Bypass, VMScape, WhatsApp Worm & More

October 6, 2025
Cloud Computing on the Rise: Market Projected to Reach .6 Trillion by 2030

Cloud Computing on the Rise: Market Projected to Reach $1.6 Trillion by 2030

August 1, 2025
Stocks making the biggest moves midday: Autodesk, PayPal, Rivian, Nebius, Waters and more

Stocks making the biggest moves midday: Autodesk, PayPal, Rivian, Nebius, Waters and more

July 14, 2025
The Ultimate MSP Guide to Structuring and Selling vCISO Services

The Ultimate MSP Guide to Structuring and Selling vCISO Services

February 19, 2025
Translators’ Voices: China shares technological achievements with the world for mutual benefit

Translators’ Voices: China shares technological achievements with the world for mutual benefit

June 3, 2025

PTechHub

A tech news platform delivering fresh perspectives, critical insights, and in-depth reporting — beyond the buzz. We cover innovation, policy, and digital culture with clarity, independence, and a sharp editorial edge.

Follow Us

Industries

  • AI & ML
  • Cybersecurity
  • Enterprise IT
  • Finance
  • Telco

Navigation

  • About
  • Advertise
  • Privacy & Policy
  • Contact

Subscribe to Our Newsletter

  • About
  • Advertise
  • Privacy & Policy
  • Contact

Copyright © 2025 | Powered By Porpholio

No Result
View All Result
  • News
  • Industries
    • Enterprise IT
    • AI & ML
    • Cybersecurity
    • Finance
    • Telco
  • Brand Hub
    • Lifesight
  • Blogs

Copyright © 2025 | Powered By Porpholio