According to reports, a new Android malware is circulating under the guise of a fake chat application that is being distributed through WhatsApp.This malware is discovered to belong to the APT Bahamut and has some footprints of tactics used by the DoNot APT. This malicious Android application is initially termed “Coverlm” which is installed under the name “SafeChat” on Android devices.This application’s user interface seems to be deceiving and would convince any Android user that it is a legitimate chat application. However, once installed, the malware exploits unsuspected Android libraries for extracting and transmitting the data to a C&C (Command and Control) server.This android malware seems to be targeting individuals in the South Asian region.As previously stated, the app appears as a chat app and requests permission upon opening.It asks for the “ignore battery optimization” permission which lets the application run on the backend and communicate with the C&C smoothly.Ignore Battery Optimisation (Source: CYFIRMA)Upon providing the permission, the signup page appears. Proceeding further, the application asks for another permission under the question, “This permission is required to function properly,” which, when “allowed,” takes the victim to the Accessibility settings.Unknown permission asked by the application (Source: CYFIRMA)This permission pops up again and
Read More









