- Sophos scientists found a new variant of Pjobrat
- Android Rat is now targeting Taiwanese users
- Rotten can run Shell commands and Exfiltrate data
Pjobrat, an Android Remote Access Trojan (Rotte), which disappeared for approx. Six years ago, have made a pretty quiet comeback and targeted users with some undoubtedly more dangerous functionalities.
CyberSecurity scientists from Sophos’ X-Oops security team discovered new tests in nature and noticed that in 2019 Pjobrat could steal SMS messages, telephone contacts, device and appinformation, documents and media files from infected Android devices.
The new variant can also run Shell commands: “This increases enormous capacities on malware, allowing the threat actor much greater control over the victims’ mobile devices,” explains Sophos. “It can allow them to steal data – including WhatsApp data – from any app on the device, mess to the device itself, use the victim’s device to target and penetrate other systems on the network and even silently remove malware when their target is completed.”
Inactive campaign
The 2019 variant was mostly targeted at Indian military staff by counterfeit various dating and instant messaging apps.
The new variant seems to have dug the dating angle and focuses solely on being an instant messaging app.
In fact, Sophos says apps actually work and that the victims, if they knew each other’s IDs, could even communicate to each other.
When we talk about the victims, attackers are no longer targeted at Indians and have instead switched to the Taiwanes.
Some of the apps found in nature are called ‘Sangaallite’ (possibly a typosquatted version of ‘Signallite’, an app used in the 2021 campaigns) and CChat (forgery of a legitimate app of the same name).
Apps were distributed through WordPress sites, Sophos said, hinting at they can’t be found in popular app stores. The websites have since been closed, which means the campaign is likely to be completed, but the researchers reported them to WordPress anyway.
“This campaign therefore ran for at least 22 months, and maybe as long as two and a half years,” it was sad. However, it does not seem to have been a big or successful campaign as the public was not the goal.