Close Menu
    DevStackTipsDevStackTips
    • Home
    • News & Updates
      1. Tech & Work
      2. View All

      Sunshine And March Vibes (2025 Wallpapers Edition)

      May 16, 2025

      The Case For Minimal WordPress Setups: A Contrarian View On Theme Frameworks

      May 16, 2025

      How To Fix Largest Contentful Paint Issues With Subpart Analysis

      May 16, 2025

      How To Prevent WordPress SQL Injection Attacks

      May 16, 2025

      Microsoft has closed its “Experience Center” store in Sydney, Australia — as it ramps up a continued digital growth campaign

      May 16, 2025

      Bing Search APIs to be “decommissioned completely” as Microsoft urges developers to use its Azure agentic AI alternative

      May 16, 2025

      Microsoft might kill the Surface Laptop Studio as production is quietly halted

      May 16, 2025

      Minecraft licensing robbed us of this controversial NFL schedule release video

      May 16, 2025
    • Development
      1. Algorithms & Data Structures
      2. Artificial Intelligence
      3. Back-End Development
      4. Databases
      5. Front-End Development
      6. Libraries & Frameworks
      7. Machine Learning
      8. Security
      9. Software Engineering
      10. Tools & IDEs
      11. Web Design
      12. Web Development
      13. Web Security
      14. Programming Languages
        • PHP
        • JavaScript
      Featured

      The power of generators

      May 16, 2025
      Recent

      The power of generators

      May 16, 2025

      Simplify Factory Associations with Laravel’s UseFactory Attribute

      May 16, 2025

      This Week in Laravel: React Native, PhpStorm Junie, and more

      May 16, 2025
    • Operating Systems
      1. Windows
      2. Linux
      3. macOS
      Featured

      Microsoft has closed its “Experience Center” store in Sydney, Australia — as it ramps up a continued digital growth campaign

      May 16, 2025
      Recent

      Microsoft has closed its “Experience Center” store in Sydney, Australia — as it ramps up a continued digital growth campaign

      May 16, 2025

      Bing Search APIs to be “decommissioned completely” as Microsoft urges developers to use its Azure agentic AI alternative

      May 16, 2025

      Microsoft might kill the Surface Laptop Studio as production is quietly halted

      May 16, 2025
    • Learning Resources
      • Books
      • Cheatsheets
      • Tutorials & Guides
    Home»Development»Transparent Tribe’s Android Spyware Targets Gamers and Weapons Enthusiasts

    Transparent Tribe’s Android Spyware Targets Gamers and Weapons Enthusiasts

    July 3, 2024

    A Pakistan-linked hacking group has unleashed an updated version of its Android spyware, expanding its reach to target mobile gamers, weapons enthusiasts and TikTok users, according to cybersecurity researchers.

    The researchers identified four new malicious Android apps associated with Transparent Tribe, a group suspected of ties to Pakistani state interests. The apps continue the hackers’ strategy of embedding spyware into seemingly innocuous video browsing applications.

    Evolving Tactics of Transparent Tribe

    Transparent Tribe, also known as APT 36, has targeted Indian government and military personnel since at least 2016. The group is known to rely heavily on social engineering to deliver Windows and Android spyware through phishing emails and compromised websites.

    Researchers from SentinelLabs identified the newly discovered apps masquerading as YouTube or TikTok video players, an app for lewd videos, a mobile gaming portal, and a weapons enthusiast app. When installed, they request extensive permissions to access the device’s location, contacts, SMS messages, call logs, camera and microphone.

    Source: sentinelone.com Source: sentinelone.com

    While the permissions requested are similar to those in the previous campaign, the reduction in permissions suggests the app developers are focused on making CapraRAT a surveillance tool more than a fully featured backdoor.

    Researchers noted that the new CapraRAT APK files contained references to Android’s Oreo version (Android 8.0), released in 2017. Previous versions relied on the device running Lollipop (Android 5.1), which was released in 2015 and less likely to be compatible with modern Android devices.

    The new CapraRAT packages also contain a minimal new class called WebView, responsible for maintaining compatibility with older versions of Android via the Android Support Library. This update allows the app to run smoothly on modern versions of Android, such as Android 13 and 14.

    All four newly discovered apps communicate with the same command-and-control server, using either the domain shareboxs[.]net or a hardcoded IP address. This infrastructure has been linked to Transparent Tribe operations since at least 2022.

    Researcher Recommendations

    Cybersecurity experts recommend users exercise caution when installing apps, especially those from unofficial sources. Users should critically evaluate requested permissions and be wary of apps that ask for access unrelated to their stated purpose.

    Organizations dealing with sensitive information should implement mobile device management solutions and educate employees about the risks of installing unauthorized apps. For example, an app that only displays TikTok videos does not need the ability to send SMS messages, make calls, or record the screen.

    The researchers have advised professionals to treat the use of port 18582 as suspect, along with other indicators of compromise in their report, such as SHA1 checksums for files used in the campaign along with domain/IP network indicators.

    Source: Read More

    Facebook Twitter Reddit Email Copy Link
    Previous ArticleSouth Korean ERP Vendor’s Server Hacked to Spread Xctdoor Malware
    Next Article AI in the workplace: The good, the bad, and the algorithmic

    Related Posts

    Security

    Nmap 7.96 Launches with Lightning-Fast DNS and 612 Scripts

    May 17, 2025
    Common Vulnerabilities and Exposures (CVEs)

    CVE-2025-40906 – MongoDB BSON Serialization BSON::XS Multiple Vulnerabilities

    May 17, 2025
    Leave A Reply Cancel Reply

    Continue Reading

    RailTel and Cylus Join Forces to Strengthen Cybersecurity in Indian Railways

    Development

    CVE-2025-0856 – WordPress PGS Core Plugin Unauthenticated Remote Data Manipulation

    Common Vulnerabilities and Exposures (CVEs)

    Microsoft says Edge 134 is the fastest version of the browser ever

    Operating Systems

    Top ChatGPT Courses in 2024

    Development
    GetResponse

    Highlights

    CSS Hover Effects: 40 Engaging Animations To Try

    December 18, 2024

    Don’t come for my head, but I think it’s safe to say that static websites…

    CVE-2025-4342 – D-Link DIR-600L Remote Buffer Overflow Vulnerability

    May 6, 2025

    Debian 13 ‘Trixie’: What’s New in the Next Linux Powerhouse

    May 2, 2025

    CVE-2025-4638 – PCL Zlib Inftrees Pointer Arithmetic Vulnerability

    May 14, 2025
    © DevStackTips 2025. All rights reserved.
    • Contact
    • Privacy Policy

    Type above and press Enter to search. Press Esc to cancel.