Published on April 12, 2024. EST READ TIME: 2 minutes
Slovak cybersecurity firm ESET uncovers the eXotic Visit Android malware campaign, active since November 2021, targeting users in South Asia, particularly India and Pakistan. Utilizing fake messaging apps and other services as a disguise, the campaign distributes the Android XploitSPY RAT, gathering sensitive data and executing espionage activities. The malware's sophistication includes obfuscation techniques, emulator detection, and a native library for hiding command-and-control server information. Although primarily distributed through dedicated websites, some apps made their way onto the official Google Play Store. With victims totaling approximately 380, the campaign underscores the ongoing threat posed by targeted Android malware, emphasizing the need for robust cybersecurity measures in the region.