PULSE NAME
New surveillanceware in Google Play with ties to known threat actor targeting the Middle East
WHITE AlienVault 2018-04-17 Modified: 2018-04-17
18
IOCs
MEDIUM VOLUME
Lookout researchers have identified a new, highly targeted surveillanceware family known as Desert Scorpion in the Google Play Store. Lookout notified Google of the finding and Google removed the app immediately while also taking action on it in Google Play Protect. The app ties together two malware families - Desert Scorpion and another targeted surveillanceware family named FrozenCell - that we believe are being developed by a single, evolving surveillanceware actor called APT-C-23 targeting individuals in the Middle East.
Indicators of Compromise (18)
All URL domain FileHash-SHA1
TYPEINDICATORDESCRIPTIONCREATED
URL https://drive.google.com/uc?authuser=0&id=1cHHFMm-NiJejIE4xZxXHKGGYtxti4Gjs&export=download 2018-04-17
URL https://doc-04-9g-docs.googleusercontent.com/docs/securesc/ha0ro937gcuc7l7deffksulhg5h7mbp1/khq1nnes98sbmo0hnca368hdr5d37lko/1521280800000/14075706053171650887/*/1cHHFMm-NiJejIE4xZxXHKGGYtxti4Gjs?e=download 2018-04-17
domain dachfunny.club 2018-04-17
domain dardash.fun 2018-04-17
domain dardash.info 2018-04-17
FileHash-SHA1 38c8aa9e26feb39a30c0f2a3f005d655346656ff 2018-04-17
FileHash-SHA1 45438db970c8e8f2f795eccc04f3b04a7ae4da1b 2018-04-17
FileHash-SHA1 550efd7749c22ea4a29ff301e599c004a966052a 2018-04-17
FileHash-SHA1 6a8b5360a9231461790db01f3b0bb74f9e168956 2018-04-17
FileHash-SHA1 7461a68684f14935d59b62ac5cc6d15e566074da 2018-04-17
FileHash-SHA1 953079b78bbb28cef69eeb7a713793b3c35c33e7 2018-04-17
FileHash-SHA1 9e394dd43a90a801bcb2dbf652f2cad2b46398d7 2018-04-17
FileHash-SHA1 bba04f650024a582df2abb7d2754b1e96173632b 2018-04-17
FileHash-SHA1 c8464d725d8718643195bd7831e30123036ce80a 2018-04-17
FileHash-SHA1 dffec2a8c158c2e615d19ab908f0d40a4a731c3f 2018-04-17
FileHash-SHA1 e631022b3406920a28841df3c4b4fb953732310c 2018-04-17
FileHash-SHA1 edd4d5ff0631a406901e23fb1918f953e4e3f71b 2018-04-17
FileHash-SHA1 fb13cf63858dbeab0d790be9f964d4173d62f3c6 2018-04-17