Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.


04:30 PM
Connect Directly

5-Year-Long Cyber Espionage Campaign Hid in Google Play

OceanLotus targeted Android devices in the so-called PhantomLance campaign.

[This article was updated to include information on BlackBerry's research on this OceanLotus attack campaign]

A targeted cyber-spying mission waged by a notorious hacking team out of Vietnam preyed mainly on Android users in Southeast Asia and evaded detection in Google Play, APKpure, and other app markets for five years. 

Researchers at Kaspersky today revealed details of their study of the attack campaign they call PhantomLance, which they believe is the handiwork of OceanLotus. While Kaspersky has a policy of not tying attack groups with specific nation-states, OceanLotus long has been believed to be a Vietnamese advanced persistent threat (APT) group. PhantomLance — which targets Android — has managed to stay alive by changing up its malware along the way to evade detection.

Researchers at BlackBerry last October in their mobile threat report published their own findings on this same attack campaign, which they dubbed Operation Oceanmobile, citing three fake Android apps that OceanLotus distributed both via phishing emails and on Google Play and other stores. 

Kaspersky researchers did not cite BlackBerry's research in their findings published yesterday, but noted that their report included fresh details on the attacks. "In our research on PhantomLance we aimed to heavily focus on the technical and attribution aspects of the campaign. We were able to discover and connect dozens of samples, trace and monitor the actor's infrastructure, and bring other technical evidence that can help others to protect themselves from the threat and also to better understand the tactics, techniques and procedures of the actor," says Alexey Firsh, security researcher with Kaspersky. "We haven't seen all of these things in other reports on presumably the same topic, and that is why we decided to publish our research."

Firsh says he and his team decided to dig deeper into a Trojan backdoor that was first revealed in a July 2019 report by researchers at Dr. Web. The relatively unusual backdoor, they found, dated back to at least December 2015, the registration date of one of the domains used in the campaign, according to Firsh. The latest sample of the spying malware was present in apps on Google Play in November 2019, he says, when Kaspersky notified Google. The apps, which were a mix of dozens of consumer utility-type apps such as ad blockers, Flash plug-ins, cache cleaners, and updaters, as well Vietnamese apps for locating nearby bars and churches, were then removed from the Google Play store.

Unlike most malicious mobile apps, PhantomLance is all about targeting, and not wide-net infections or promoting its installation. The attackers created several versions of the backdoor, with dozens of samples, and when an app first went up in Google Play or other app stores, it didn't contain malware: That was added later in the form of an update, after the user had installed it. That's likely what allowed the apps to pass any app store vetting.

There have been some 300 attack attempts on Androids in India, Vietnam, Bangladesh, and Indonesia, since 2016.

OceanLotus, aka APT32, for years has been spotted targeting Vietnamese citizens and dissidents and journalists, as well as industries in Germany, China, the Philippines, the US, and the UK, in traditional cyber espionage fashion. The group, believed to be backed by the Vietnam government, in 2014 hacked a European company that planned to build a manufacturing plant in Vietnam, as well as a hospitality developer in 2016 that was looking to do business in Vietnam. 

Opsec Game on Point
The malware performs the usual spy stuff, gathering geolocation information, call logs, contact lists, and SMS messages, as well as information on the victim's device, such as model, operating system, and installed apps. "But we see that it also has the ability to execute special shell commands from the [C2] server and download additional payloads on the victim's device," Firsh explains.

Another tactic the attackers employed: creating a fake developer profile on GitHub to appear as a legitimate app developer. "I think the main reason they have those accounts is to start background stories to developers to look more legitimate to moderators of the marketplaces," explains Lev Pikman, a Kaspersky researcher who worked with Firsh on the PhantomLance research

BlackBerry also noted the Github accounts in its research. "They created modified GitHub repositories that theoretically showed evidence of the developers’ code for each app, complete with public facing 'contact us' email addresses to answer any questions that might arise about their 'products.'" BlackBerry's report said. "They even went to lengths to concoct entire privacy policies for their apps, which few people tend to actually read, but nevertheless was ironic, given that OCEANLOTUS' entire premise was to spy on its targets."

Kaspersky's Firsh says the attack group employs different encryption keys, separate infrastructures, and other methods to cover its tracks. "They are pretty good at opsec," he says.

While defending against a nation-state is not so simple, the best bet is to have a mobile security tool or service for devices and to be wary of apps you download, experts say.

The researchers presented their findings at Kaspersky's online Security Analyst Summit today, which was kicked off by Eugene Kaspersky, founder and CEO of Kaspersky, who cited an increase in malicious online activity since much of the world went into quarantine stay-at-home due to the COVID-19 pandemic. "Now [attackers] have many more opportunities to do their business," Kaspersky said. "We have seen a 10% increase in the new malware we collect. ... In some specific nations, we see ... more attempts at attack."

Related Content:

Check out The Edge, Dark Reading's new section for features, threat data, and in-depth perspectives. Today's top story: "5 Ways to Prove Security's Worth in the Age of COVID-19.

Kelly Jackson Higgins is the Executive Editor of Dark Reading. She is an award-winning veteran technology and business journalist with more than two decades of experience in reporting and editing for various publications, including Network Computing, Secure Enterprise ... View Full Bio

Recommended Reading:

Comment  | 
Print  | 
More Insights
Newest First  |  Oldest First  |  Threaded View
User Rank: Apprentice
5/10/2020 | 1:38:26 AM
Its is really a good story for me.

I am site engineer and presently taking a shot at site Pak24tv. Pak24tv is a greater site and live television entrance in Pakistan. You can watch upto 80 live gushing channel free and can check any portable cost and determination in any nation. You can likewise understand sites and check any sim bundle. On the off chance that you need to visit site, at that point click
FluBot Malware's Rapid Spread May Soon Hit US Phones
Kelly Sheridan, Staff Editor, Dark Reading,  4/28/2021
7 Modern-Day Cybersecurity Realities
Steve Zurier, Contributing Writer,  4/30/2021
How to Secure Employees' Home Wi-Fi Networks
Bert Kashyap, CEO and Co-Founder at SecureW2,  4/28/2021
Register for Dark Reading Newsletters
White Papers
Cartoon Contest
Current Issue
2021 Top Enterprise IT Trends
We've identified the key trends that are poised to impact the IT landscape in 2021. Find out why they're important and how they will affect you today!
Flash Poll
How Enterprises are Developing Secure Applications
How Enterprises are Developing Secure Applications
Recent breaches of third-party apps are driving many organizations to think harder about the security of their off-the-shelf software as they continue to move left in secure software development practices.
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
PUBLISHED: 2021-05-07
An issue was discovered on Tenda AC11 devices with firmware through A stack buffer overflow vulnerability in /goform/setmac allows attackers to execute arbitrary code on the system via a crafted post request.
PUBLISHED: 2021-05-07
An issue was discovered on Tenda AC11 devices with firmware through A stack buffer overflow vulnerability in /gofrom/setwanType allows attackers to execute arbitrary code on the system via a crafted post request. This occurs when input vector controlled by malicious attack get copie...
PUBLISHED: 2021-05-07
An issue was discovered on Tenda AC11 devices with firmware through A stack buffer overflow vulnerability in /goform/setVLAN allows attackers to execute arbitrary code on the system via a crafted post request.
PUBLISHED: 2021-05-07
An issue was discovered on Tenda AC11 devices with firmware through A stack buffer overflow vulnerability in /goform/setportList allows attackers to execute arbitrary code on the system via a crafted post request.
PUBLISHED: 2021-05-07
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit Reader User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the handlin...