City
Epaper

Meta shuts Pak hackers targeting Indian officials via honey trapping, malware

By IANS | Updated: August 5, 2022 16:10 IST

New Delhi, Aug 5 Meta (formerly Facebook) has cracked down on a cyber espionage operation linked to state-sponsored ...

Open in App

New Delhi, Aug 5 Meta (formerly Facebook) has cracked down on a cyber espionage operation linked to state-sponsored bad actors in Pakistan that targeted people in India, including military personnel and government officials, with various methods like honey trapping and infiltrating their devices with malware.

Apart from India, the group of hackers in Pakistan known in the security industry as APT36 targeted people in Afghanistan, Pakistan, the UAE and Saudi Arabia, according to Meta's quarterly 'Adversarial Threat Report'.

"Our investigation connected this activity to state-linked actors in Pakistan," Meta said.

The group's activity was persistent and targeted many services across the Internet from email providers to file-hosting services to social media.

"APT36 used various malicious tactics to target people online with social engineering to infect their devices with malware. They used a mix of malicious and camouflaged links, and fake apps to distribute their malware targeting Android and Windows-run devices," the social network warned.

APT36 used fictitious personas posing as recruiters for both legitimate and fake companies, military personnel or attractive young women looking to make a romantic connection in an attempt to build trust with the people they targeted.

The group deployed a wide range of tactics, including the use of custom infrastructure, to deliver their malware.

"Some of these domains masqueraded as photo-sharing websites or generic app stores, while others spoofed the domains of real companies like the Google Play Store, Microsoft's OneDrive, and Google Drive," said the Meta report.

Additionally, this group used common file-sharing services like WeTransfer to host malware for short periods of time.

The Pakistan-based actors also used link-shortening services to disguise malicious URLs.

They used social cards and preview sites online tools used in marketing to customise what image is displayed when a particular URL is shared on social media to mask redirection and ownership of domains APT36 controlled.

"APT36 didn't directly share malware on our platforms, but rather used the tactics to share malicious links to sites they controlled and where they hosted malware," said Meta.

In several cases, this group used a modified version of commodity Android malware known as 'XploitSPY' available on Github.

While 'XploitSPY' appears to have been originally developed by a group of self-reported ethical hackers in India, APT36 made modifications to it to produce a new malware variantAcalled 'LazaSpy'.

Meta found that in this recent operation, APT36 had also trojanised (non-official) versions of WhatsApp, WeChat and YouTube with another commodity malware family known as Mobzsar or CapraSpy.

"Both malware families are capable of accessing call logs, contacts, files, text messages, geolocation, device information, photos and enabling microphone," said the report.

Meta also removed a brigading network in India, a mass reporting network in Indonesia and coordinated violating networks in Greece, India, and South Africa.

Brigading is a technique where groups of people coordinate to harass people on Meta platforms in an attempt to intimidate and silence them.

Disclaimer: This post has been auto-published from an agency feed without any modifications to the text and has not been reviewed by an editor

Tags: MetapakistanNew DelhiFacebookThe new delhi municipal councilDhs punjabDelhi south-westFacebook connectivityAfter facebookNl salviCs - connectivity
Open in App

Related Stories

InternationalIran Terrorist Attack Video: At Least 8 Killed, 13 Injured in Zahedan Firing; Pakistani Group Claims Responsibility

MumbaiMumbai: Uttarakhand Woman Sexually Assaulted in Andheri Hotel by Facebook Friend; Accused Arrested

EntertainmentPakistani Actress Humaira Asghar Dies At 32, Decomposed Body Found in Karachi Home by Local Police

MaharashtraRaigad: Suspicious Pakistani Boat in Arabian Sea Turns Out to Be Buoy

OpinionsVicious Plot to Drown Nation in Drugs

Technology Realted Stories

TechnologyKarnataka govt to host Nobel laureates for landmark 'Quantum Dialogue' tomorrow

TechnologyTop firms offering 1.18 lakh internships to youths under PM's scheme: Minister

TechnologyBoeing reports net loss of $612 million in Q2 2025

Technology16,912 Jan Aushadhi Kendras operational till June, citizens save Rs 38,000 cr: Minister

TechnologyIndia’s green steel demand to soar to 179 million tons by 2050: Report