#1 Middle East & Africa Trusted Cybersecurity News & Magazine |

36 C
Dubai
Sunday, June 1, 2025
HomeAsiaBeware of Hidden Visitors: New Android Spyware Targets South Asia

Beware of Hidden Visitors: New Android Spyware Targets South Asia

Date:

Related stories

spot_imgspot_imgspot_imgspot_img

Mobile phone users in Pakistan and India are on high alert following the discovery of a new espionage campaign targeting Android devices. Cybersecurity researchers at ESET revealed details of this campaign, dubbed “eXotic Visit,” which highlights the evolving tactics of cybercriminals and the importance of vigilance.

Let’s dissect the campaign, understand the malware used, and explore ways to stay protected from such threats.

eXotic Visit: A Clandestine Operation

ESET researchers identified eXotic Visit as active between November 2021 and the end of 2023. The campaign primarily targeted Android users in Pakistan and India through seemingly legitimate messaging apps. These apps, however, were malicious and designed to compromise devices upon installation.

XploitSPY: The Malware Behind the Scenes

The campaign leveraged a Remote Access Trojan (RAT) called XploitSPY. This malware, initially uploaded to GitHub in 2020, grants attackers extensive control over infected devices, including:

  • Stealing sensitive data like contacts, call logs, SMS messages, and even browsing history.
  • Enabling microphone and camera access for real-time surveillance.
  • Exfiltrating data from the device to a remote server controlled by the attackers.

Distribution Channels: How Did It Spread?

While the specific methods used by eXotic Visit remain under investigation, researchers suspect the malicious apps were initially distributed on dedicated websites. ESET also identified instances of these apps appearing on the Google Play Store, highlighting the need for caution even in official app stores.

10 Ways to Fortify Your Android Device

Here are 10 actionable steps Android users can take to protect themselves from espionage campaigns like eXotic Visit:

  1. Maintain Software Updates: Ensure your Android device and all apps are updated with the latest security patches to address known vulnerabilities.
  2. Download Apps Only from Trusted Sources: Download apps only from the official Google Play Store or reputable app stores. Be wary of downloading apps from unknown sources.
  3. Read App Reviews and Permissions: Before installing an app, carefully read user reviews and scrutinize the permissions it requests. Avoid apps requesting excessive permissions that seem unnecessary for their function.
  4. Use a Mobile Security Solution: Consider using a reputable mobile security solution that can detect and block malware, phishing attempts, and other mobile threats.
  5. Be Cautious of Unfamiliar Links: Don’t click on suspicious links or attachments received through messages or emails, even if they appear to come from known contacts.
  6. Enable Two-Factor Authentication (2FA): Whenever possible, enable two-factor authentication on your accounts to add an extra layer of security beyond passwords.
  7. Beware of Fake Messaging Apps: Be skeptical of messaging apps with unfamiliar names or logos. Research the app’s developer and legitimacy before installation.
  8. Review App Permissions Regularly: Periodically review the permissions granted to your installed apps and revoke any that seem unnecessary.
  9. Back Up Your Data: Regularly back up your critical data to facilitate recovery in case your device gets compromised.
  10. Stay Informed: Keep yourself updated on the latest cybersecurity threats and best practices for mobile security.

Conclusion

The eXotic Visit campaign serves as a stark reminder of the ever-present threat of mobile malware. By staying vigilant, adopting secure app download practices, and implementing recommended security measures, Android users can significantly reduce their risk of falling victim to such espionage campaigns. It’s also crucial for app stores like Google Play Store to strengthen their vetting processes to prevent malicious apps from reaching users in the first place.

Ouaissou DEMBELE
Ouaissou DEMBELEhttp://cybercory.com
Ouaissou DEMBELE is a seasoned cybersecurity expert with over 12 years of experience, specializing in purple teaming, governance, risk management, and compliance (GRC). He currently serves as Co-founder & Group CEO of Sainttly Group, a UAE-based conglomerate comprising Saintynet Cybersecurity, Cybercory.com, and CISO Paradise. At Saintynet, where he also acts as General Manager, Ouaissou leads the company’s cybersecurity vision—developing long-term strategies, ensuring regulatory compliance, and guiding clients in identifying and mitigating evolving threats. As CEO, his mission is to empower organizations with resilient, future-ready cybersecurity frameworks while driving innovation, trust, and strategic value across Sainttly Group’s divisions. Before founding Saintynet, Ouaissou held various consulting roles across the MEA region, collaborating with global organizations on security architecture, operations, and compliance programs. He is also an experienced speaker and trainer, frequently sharing his insights at industry conferences and professional events. Ouaissou holds and teaches multiple certifications, including CCNP Security, CEH, CISSP, CISM, CCSP, Security+, ITILv4, PMP, and ISO 27001, in addition to a Master’s Diploma in Network Security (2013). Through his deep expertise and leadership, Ouaissou plays a pivotal role at Cybercory.com as Editor-in-Chief, and remains a trusted advisor to organizations seeking to elevate their cybersecurity posture and resilience in an increasingly complex threat landscape.

Subscribe

- Never miss a story with notifications

- Gain full access to our premium content

- Browse free from up to 5 devices at once

Latest stories

spot_imgspot_imgspot_imgspot_img

LEAVE A REPLY

Please enter your comment!
Please enter your name here