Fake Android chat app lets hackers steal Signal, WhatsApp user data


Experts have raised the alarm about yet another case of Android malware under the cover of a dodgy app, this time spreading across South Asian countries.
According to cybersecurity company Cyfirma, the “dummy chatting app” which goes by the name Safe Chat on victims’ devices is said to have higher levels of permissions compared with another similar instance of malware that it has been compared to.
After analyzing the malware, Cyfirma has revealed suspicions that the latest attack is yet another by Indian APT hacking group Bahamut.
Safe Chat app is… not safe
Once delivered via WhatsApp and installed, the Safe Chat app throws up a series of pop-up messages, including one asking the victim to allow background activity and to ignore battery optimizations, in turn granting the attacker continuous access to the infected device.
A second pop-up seeks permission to the device’s accessibility features, and as such, information such as keystrokes. Other information that the threat actor can get access to includes a victim’s precise location, contacts, file storage, SMS messages, and call logs.
The spyware is suspected to be a variant of Coverlm, which has previously been seen targeting data from apps like WhatsApp, Signal, and Telegram. The researchers also noted a similarity in the tactics seen in both this campaign and another by APT DoNot, both of which targeting the same geography and with a focus on espionage.
Cyfirma says that, taking into account its findings, its “analysis strongly indicates that the APT group behind the attack has ties to the Indian territory and is acting in the interest of one nation state government.”
When TechRadar Pro asked Google for more information about the previous DoNot attack, a company spokesperson confirmed that the malicious apps had been removed from the Play Store.
We were also told that “Google Play Protect protects users from apps known to contain this malware on Android devices with Google Play Services, even when those apps come from other sources.”
The company did not immediately respond to our request for comment specific to this example.
Experts have raised the alarm about yet another case of Android malware under the cover of a dodgy app, this time spreading across South Asian countries. According to cybersecurity company Cyfirma, the “dummy chatting app” which goes by the name Safe Chat on victims’ devices is said to have higher…
Recent Posts
- Google may be close to launching YouTube Premium Lite
- Someone wants to sell you a digital version of the antiquated typewriter but without a glued-on keyboard (no really)
- This is probably the best looking docking station I’ve ever seen in my entire life – and I can’t wait to test it
- Fitbit’s got a battery problem
- Adidas plugs its website and app into Amazon’s ‘Buy with Prime’ program
Archives
- February 2025
- January 2025
- December 2024
- November 2024
- October 2024
- September 2024
- August 2024
- July 2024
- June 2024
- May 2024
- April 2024
- March 2024
- February 2024
- January 2024
- December 2023
- November 2023
- October 2023
- September 2023
- August 2023
- July 2023
- June 2023
- May 2023
- April 2023
- March 2023
- February 2023
- January 2023
- December 2022
- November 2022
- October 2022
- September 2022
- August 2022
- July 2022
- June 2022
- May 2022
- April 2022
- March 2022
- February 2022
- January 2022
- December 2021
- November 2021
- October 2021
- September 2021
- August 2021
- July 2021
- June 2021
- May 2021
- April 2021
- March 2021
- February 2021
- January 2021
- December 2020
- November 2020
- October 2020
- September 2020
- August 2020
- July 2020
- June 2020
- May 2020
- April 2020
- March 2020
- February 2020
- January 2020
- December 2019
- November 2019
- September 2018
- October 2017
- December 2011
- August 2010