Russian-linked spyware 'among most sophisticated ever discovered'

Monokle spyware boasts extensive list of potential hacking tools

A highly sophisticated strain of Android spyware has been discovered which is thought to be linked to a Russian defence contractor previously implicated in the interference of the US 2016 presidential elections.

Researchers from Lookout say the dangerous spyware, known as Monokle, can perform a range of hacking tasks, such as exfiltrating sensitive data, issuing remote access commands on devices, and launching man-in-the-middle attacks (MITM).

The spyware, which has been traced back to the Special Technology Centre (STC), a St. Petersberg-based company with a previously unknown history of developing apps, has been actively infecting users since 2016. Activity has been low in volume but consistent throughout the years, peaking in 2018.

Monokle has so far operated as a trojan, embedding itself into popular apps such as Evernote, Wickr and Skype and then launching a varied list of attack types from a user's machine. It tricks users into downloading it by disguising itself as popular legitimate apps such as encrypted messaging services, productivity boosters and Android update services. It spoofs these apps logos and offers seemingly legitimate functionality.

It's believed that Monokle operates entirely on the Android operating system. While there is evidence of an iOS version in development, researchers said there have been no observed active infections on Apple's operating system to date.

If a user does find themselves infected with this intensely effective and capable strain of spyware, they will be prey to the array of malicious features. The spyware is said to be invisible to an infected device's Process Manager and, because of its remote access trojan (RAT) functionality, it's likely it would record most of your calls and background audio, and keep logs of texts, calls, passwords and pin codes.

Data exfiltration is also a big part of Monokle's functionality. It's said to have the ability to retrieve calendar information, including the date and time of an event, and the description of it. It can also collect account information from some of the most popular social media apps around, including Instagram, WhatsApp and Skype.

In addition, Monokle can retrieve contacts, emails, call and browsing histories, accounts with corresponding passwords and track device location. It can also install attacker-specified certificates to the Android trusted-certificate store, which would allow it to conduct man-in-the-middle (MITM) attacks against TLS traffic.

Researchers were unable to access any of Monokle's exfiltrated data and can only speculate on the potential targets of the spyware, but possibilities listed include those interested in Isalm, interested in or associated with the Ahrar al-Sham militant group in Syria and those living in or associated the Caucasus regions of Eastern Europe - among others.

These guesses were made through inferred information such as the namings of Monokle-infected apps such as 'Ahrar Maps' and 'caucus'. Most apps were written in English but some were also in Russian and Arabic.

The researchers "found strong links that tie STC's Android software development operations to Monokle's indicators of compromise (IOCs) [and] shared command and control infrastructure used by both legitimate and malicious Android applications produced by STC," the report read.

"The Defender application and related software has been referred to by an STC developer as developed 'for a government customer,'" it added.

The report's findings have forced experts to once again raise awareness of the necessity of only downloading verified apps from legitimate sources.

"The Monokle malware mainly infects devices through corrupted versions of legitimate apps," said Paul Bischoff, privacy advocate, Comparitech.com. "For this reason, it's important for all Android users to get apps from a trusted source."

"Avoid downloading apps from third-party app stores and APK downloads," he added. "App developers don't publish their apps on these sites, so they're put there by unknown third parties. The apps from unreputable sources often look identical, but in fact, contain malware."

Featured Resources

The ultimate law enforcement agency guide to going mobile

Best practices for implementing a mobile device program

Free download

The business value of Red Hat OpenShift

Platform cost savings, ROI, and the challenges and opportunities of Red Hat OpenShift

Free download

Managing security and risk across the IT supply chain: A practical approach

Best practices for IT supply chain security

Free download

Digital remote monitoring and dispatch services’ impact on edge computing and data centres

Seven trends redefining remote monitoring and field service dispatch service requirements

Free download

Recommended

Malware developers create malformed code signatures to avoid detection
malware

Malware developers create malformed code signatures to avoid detection

24 Sep 2021
Bahrain targets activists with NSO's Pegasus spyware
spyware

Bahrain targets activists with NSO's Pegasus spyware

24 Aug 2021
New malware uses search engine ads to target pirate gamers
malware

New malware uses search engine ads to target pirate gamers

21 Jul 2021
Nigerian cyber criminals target Texas unemployment system
cyber security

Nigerian cyber criminals target Texas unemployment system

27 May 2021

Most Popular

Best Linux distros 2021
operating systems

Best Linux distros 2021

11 Oct 2021
What is cyber warfare?
Security

What is cyber warfare?

15 Oct 2021
HPE wins networking contract with Birmingham 2022 Commonwealth Games
Network & Internet

HPE wins networking contract with Birmingham 2022 Commonwealth Games

15 Oct 2021