Menu
Browse

Cyber Incident Victim: Indian defense personnel

Date:

Nov 2022

Location:

India

Summary

A malicious Android application disguised as a promotion letter targeted Indian defense personnel, distributing a remote access trojan (Spymax RAT variant) via WhatsApp-shared Google Drive links. The malware, masquerading as an Adobe Reader look-alike, sought permissions to access cameras, microphones, internet, and storage, posing significant national security risks. Threat actors leveraged the RAT's web view feature to inject malicious links, enabling potential exfiltration of sensitive data. Cybersecurity analysts attributed the prolonged campaign to suspected nation-state actors, citing geopolitical tensions in South Asia, though definitive attribution remains unconfirmed due to insufficient evidence. The attack exploited decoy documents listing personnel promotions to compromise devices.

CIA Posture Motives Tactics, Techniques & Procedures
Available to members 1 motive 2 techniques
Threat Actors Type Location
0 actors Available to members Available to members

Description

The incident involved a malicious Android installation package targeting Indian defense personnel, with activity observed since at least July 2021. Cybersecurity firm Cyfirma identified an APK file disguised as a promotion letter to the 'Subs Naik' rank. Upon installation, the malware presented itself as an Adobe Reader application icon on the victim's device. The malicious application requested multiple permissions including access to the camera, microphone, internet connectivity, and device storage. Researchers determined that access to any single permission could create significant security risks, with potential consequences for national security due to the sensitive nature of the targets' positions.

Cyber Incident Image

Technical analysis revealed the malware was a variant of Spymax RAT, a remote access trojan with publicly available source code on underground forums. The specific build used in this campaign incorporated a web view feature enabling threat actors to inject arbitrary web links into the module. Attackers distributed the malware through a Google Drive link hosting a PDF document listing Indian defense personnel who had received promotions. This link was propagated via WhatsApp messaging platform, leveraging social engineering tactics tailored to military recipients. Cyfirma's report noted the campaign's longevity and target specificity suggested potential nation-state involvement aimed at exfiltrating sensitive information, though no conclusive attribution to specific threat actors or countries was established. The security firm contextualized the attacks within ongoing geopolitical tensions in South Asia but emphasized no direct evidence linked the operation to neighboring states at the time of reporting.

Sources
Sources available to members
1 source