Lukas Stefanko(@LukasStefanko) 's Twitter Profileg
Lukas Stefanko

@LukasStefanko

Malware Researcher at @ESET
Android security, malware analysis, app vulnerability research
https://t.co/dnQvb9BCZj
https://t.co/7RLveZTSoz

ID:2936786110

linkhttp://welivesecurity.com/author/lstefanko calendar_today22-12-2014 10:23:40

3,3K Tweets

23,8K Followers

697 Following

ESET Research(@ESETresearch) 's Twitter Profile Photo

has discovered an active campaign targeting users mainly in šŸ‡®šŸ‡³India and šŸ‡µšŸ‡°Pakistan with apps bundled with the XploitSPY malware posing mostly as messaging services. We named this campaign eXotic Visit. Lukas Stefanko welivesecurity.com/en/eset-researā€¦ 1/6

account_circle
Andy Svintsitsky(@AndySvints) 's Twitter Profile Photo

of espionage apps by Lukas Stefanko from ESET Research
ā€¢leveraged to distribute apps with code
ā€¢apps reached 1,400+ installs & are still available on alternative app stores
welivesecurity.com/en/eset-researā€¦

#VajraSpy #Patchwork of espionage apps by @LukasStefanko from @ESETresearch ā€¢leveraged #GooglePlay to distribute apps with #RAT code ā€¢apps reached 1,400+ installs & are still available on alternative app stores welivesecurity.com/en/eset-researā€¦ #Malware #Research #AndySvints #InfoSec
account_circle
Righard Zwienenberg(@RighardZw) 's Twitter Profile Photo

VajraSpy: ESET researchers discovered apps carrying VajraSpy with esp. func. It steals contacts, files, etc, some of its implementations can extract WhatsApp & Signal msg, record calls, and take pictures.

Read Lukas Stefanko's write-up here: welivesecurity.com/en/eset-researā€¦

account_circle
ESET Research(@ESETresearch) 's Twitter Profile Photo

researchers have discovered twelve apps containing RAT used by the APT group. Six of these apps had previously been available on Play; together they reached over 1,400 installs. Lukas Stefanko welivesecurity.com/en/eset-researā€¦ 1/5

#ESET researchers have discovered twelve #Android apps containing #VajraSpy RAT used by the #Patchwork APT group. Six of these apps had previously been available on #Google Play; together they reached over 1,400 installs. @LukasStefanko welivesecurity.com/en/eset-researā€¦ 1/5
account_circle
Mobile Hacker(@androidmalware2) 's Twitter Profile Photo

PoC to takeover Android using another Android by exploiting critical Bluetooth vulnerability to install payload without proper Bluetooth pairing (CVE-2023-45866)

It still affects Android 10 and bellow
mobile-hacker.com/2024/01/23/expā€¦

account_circle
ESET Research(@ESETresearch) 's Twitter Profile Photo

has observed an alarming growth of deceptive Android loan apps offering personal loans designed to defraud users and gain their personal information. Many of these apps found their way to official marketplaces.
Lukas Stefanko welivesecurity.com/en/eset-researā€¦ 1/8

account_circle
ESET Research(@ESETresearch) 's Twitter Profile Photo

has identified a watering-hole attack on the HUNZA NEWSĀ® website, where we discovered a malicious app containing we named . The site focuses on , a region administered by šŸ‡µšŸ‡° Pakistan. Lukas Stefanko welivesecurity.com/en/eset-researā€¦ 1/5

account_circle
Righard Zwienenberg(@RighardZw) 's Twitter Profile Photo

Unlucky Kamran: Android malware spying on Urdu-speaking residents of Gilgit-Baltistan.

ESET researchers discovered Kamran, a watering-hole attack on a regional news website about Gilgit-Baltistan, a disputed region.

Read Lukas Stefanko's report here: welivesecurity.com/en/eset-researā€¦

Unlucky Kamran: Android malware spying on Urdu-speaking residents of Gilgit-Baltistan. @ESET researchers discovered Kamran, a watering-hole attack on a regional news website about Gilgit-Baltistan, a disputed region. Read @LukasStefanko's report here: welivesecurity.com/en/eset-researā€¦
account_circle
David Parkinson Frost(@ParkinsonFrost) 's Twitter Profile Photo

Well, he got me šŸ„² should've pushed for the šŸ§¹ instead šŸ˜…

Wizard prodigy Harry Potter āš”ļø joins the show to talk Qakbot, Android BadBazaar espionage, UK air traffic control meltdown, and much more!

Shoutout to the FBI and U.S. Department of Justice for obliterating Qakbot, Zscaler ThreatLabz forā€¦

account_circle
Mobile Hacker(@androidmalware2) 's Twitter Profile Photo

Trojanized Android app available on Google Play and Galaxy Store could secretly autolink Signal account of victim to attacker Desktop without noticing.
This would allow attacker to have a full Signal account control of the victim without notice
welivesecurity.com/en/eset-researā€¦

account_circle
Thomas Brewster(@iblametom) 's Twitter Profile Photo

NEW - A fake Signal app popped up on Google Play using a previously-undocumented method to spy on the encrypted comms tool.

The hackers are linked to China and previous hits on the Uyghur community.

There was a fake Telegram too...

h/t Lukas Stefanko

forbes.com/sites/thomasbrā€¦

account_circle
Lukas Stefanko(@LukasStefanko) 's Twitter Profile Photo

Trojanized and apps discovered on Google Play and Galaxy Store. Espionage malware belongs to BadBazaar family

It is the first case of spying on victimā€™s Signal communication by secretly autolinking compromised device to attackerā€™s Signal
welivesecurity.com/en/eset-researā€¦

Trojanized #Signal and #Telegram apps discovered on Google Play and Galaxy Store. Espionage malware belongs to BadBazaar family It is the first case of spying on victimā€™s Signal communication by secretly autolinking compromised device to attackerā€™s Signal welivesecurity.com/en/eset-researā€¦
account_circle
Mobile Hacker(@androidmalware2) 's Twitter Profile Photo

Android installed directly from a website can bypass 'installation from untrusted sources' warning using WebAPK technology

WebAPK enables creation Android native apps from web applications
linkedin.com/pulse/using-weā€¦ credits CSIRT KNF RIFFSEC

account_circle
Lukas Stefanko(@LukasStefanko) 's Twitter Profile Photo

Swing VPN Android app with 5M+ installs can DDoS any server received from config file.
I replicated original research and the app still sends server requests every 10 seconds. I reported the app to Google Play, and it was removed within 24 hours.
Research: lecromee.github.io/posts/swing_vpā€¦

Swing VPN Android app with 5M+ installs can DDoS any server received from config file. I replicated original research and the app still sends server requests every 10 seconds. I reported the app to Google Play, and it was removed within 24 hours. Research: lecromee.github.io/posts/swing_vpā€¦
account_circle
ESET Research(@ESETresearch) 's Twitter Profile Photo

identified malware being distributed as the and Chatico messaging apps. The BingeChat campaign is still active as of this writing. Lukas Stefanko
welivesecurity.com/2023/06/15/andā€¦ 1/5

#ESETResearch identified #Android #GravityRAT malware being distributed as the #BingeChat and Chatico messaging apps. The BingeChat campaign is still active as of this writing. @LukasStefanko welivesecurity.com/2023/06/15/andā€¦ 1/5
account_circle