Bitdefender researchers discover an Italian RAT in China and Japan
Bitdefender researchers discover an Italian RAT in China and Japan

Bitdefender researchers Alin Barbatei and Marius Mihai Tivadar have discovered a new Android Remote Access Trojan (RAT) in China and Japan. The RAT is able to spy on mobile devices by taking screenshots and listening to phone calls. The data is then saved to Command & Control (C&C) servers located in Italy.

To install the spyware, the attack requires that the target device has previously been rooted. This means that it is possible to gain complete control over the entire device, bypassing the user controls built into the OS. While there are many reasons why a user will do this it also makes life easier for hackers. China Internet Watch has reported 80% of Android devices in China have been rooted.

What makes this of interest?

It is the Italian connection that makes this interesting. It selects its victims based on their International Mobile Station Equipment Identifier (IMEI). This is a unique identifier that every mobile device will have. The use of specific IMEI numbers makes this a very targeted attack. This suggests several possible targets.

Is this criminals tracking tourists that have recently visited Italy? Could it be one criminal gang spying on another? Is this a government operation that Bitdefender has stumbled upon? If so, which government? Europe is a hotbed of companies who develop spyware for governments and law enforcement. It is possible this attack is part of a campaign conducted by an Italian company on behalf of another government.

This could also be part of a much darker threat. The researchers say: “Since only advanced persistent threats (APT) normally exhibit this type of selectivity when infecting victims, this Android RAT could be part of a wider attack that is yet to be uncovered.” The Android RAT has been distributed under two package names “it.cyprus.client” and “it.assistenzaumts.update”. Despite the names there is no apparently difference in the functionality.

Conclusion

The discovery of yet another Android RAT should come as no surprise. The number of Android devices in use makes it an ideal choice for attackers. There is also an increasing number of Android devices that are never updated. This makes it much easier for hackers to attack them.

Is this just another cyberattack or is it something much more mysterious? We will have to wait a little longer to find out.

Previous articleUS health insurer suffers data breach
Next articleZero-day attack hits Irish Police
Ian Murphy
Ian Murphy is an enterprise technology journalist, podcaster, editor and industry analyst with more than 40 years' experience covering enterprise IT, cybersecurity, networking, cloud and artificial intelligence. His career combines hands-on technology experience with long-term industry analysis and journalism. In the 1980s, Ian authored an industry report on expert systems, an early application of artificial intelligence, and founded an IT training company delivering accredited training on enterprise software. He later became a Microsoft Certified Trainer, helping professionals understand and apply business technologies. Alongside his work as a freelance journalist and analyst, Ian developed software, deployed enterprise networks and managed software and technical support teams. That practical experience informs his writing, providing insight into not only what technologies promise, but how they are implemented and used in real enterprise environments. Ian has written thousands of articles, produced industry research, hosted podcasts and interviewed technology leaders across enterprise software, infrastructure, cybersecurity and AI. His work focuses on helping CIOs, IT leaders and technology professionals understand the opportunities, challenges and real-world impact of emerging technologies.

LEAVE A REPLY

Please enter your comment!
Please enter your name here