CSIDB logo
Incident

Indian defense personnel

Incident posture

Attack window
Nov 2022
Location
India
Status
Historical
CIA posture
Available to members
Updated
2025-11-19 00:00

Linked entities

Victim
Indian defense personnel
Threat actors
0 actors
Sources
1 source

Timeline

Occurred
Nov 2022
Discovered
Pending
Disclosed
Pending
Resolved
Pending

Summary

A malicious Android application disguised as a promotion letter targeted Indian defense personnel, distributing a remote access trojan (Spymax RAT variant) via WhatsApp-shared Google Drive links. The malware, masquerading as an Adobe Reader look-alike, sought permissions to access cameras, microphones, internet, and storage, posing significant national security risks. Threat actors leveraged the RAT's web view feature to inject malicious links, enabling potential exfiltration of sensitive data. Cybersecurity analysts attributed the prolonged campaign to suspected nation-state actors, citing geopolitical tensions in South Asia, though definitive attribution remains unconfirmed due to insufficient evidence. The attack exploited decoy documents listing personnel promotions to compromise devices.

Motives

Detailed motive labels are available to members.

1 motive

TTPs

Detailed technique labels are available to members.

2 techniques

Description

The incident involved a malicious Android installation package targeting Indian defense personnel, with activity observed since at least July 2021. Cybersecurity firm Cyfirma identified an APK file disguised as a promotion letter to the 'Subs Naik' rank. Upon installation, the malware presented itself as an Adobe Reader application icon on the victim's device. The malicious application requested multiple permissions including access to the camera, microphone, internet connectivity, and device storage. Researchers determined that access to any single permission could create significant security risks, with potential consequences for national security due to the sensitive nature of the targets' positions.

Technical analysis revealed the malware was a variant of Spymax RAT, a remote access trojan with publicly available source code on underground forums. The specific build used in this campaign incorporated a web view feature enabling threat actors to inject arbitrary web links into the module. Attackers distributed the malware through a Google Drive link hosting a PDF document listing Indian defense personnel who had received promotions. This link was propagated via WhatsApp messaging platform, leveraging social engineering tactics tailored to military recipients. Cyfirma's report noted the campaign's longevity and target specificity suggested potential nation-state involvement aimed at exfiltrating sensitive information, though no conclusive attribution to specific threat actors or countries was established. The security firm contextualized the attacks within ongoing geopolitical tensions in South Asia but emphasized no direct evidence linked the operation to neighboring states at the time of reporting.

Sources

Sources available to members: 1 source.

CSIDB