mimile
mimile.ai
Back to feed
This event is part of a larger story
Глобальная волна кибератак: от шпионажа до вымогательства
Read briefing

Fake Bahrain alert app installs Android spyware via phony Google Play sites

AI digest

This digest was compiled by AI from multiple sources — links to the originals are below.

Fake Bahrain alert app installs Android spyware via phony Google Play sites

A malicious Android application posing as a Bahrain civil defense alert tool delivered four-stage spyware via fake Google Play pages. The campaign exploited civilian fear during Iranian missile strikes to trick users into sideloading the malware.

The Malware Campaign

Researchers at Dark Reading identified a four-stage Android spyware campaign targeting Bahraini civilians. The malware was distributed through fake Google Play store pages mimicking legitimate alert apps. The attackers exploited the heightened fear during Iranian missile strikes in April 2024 to increase infection rates.

Technical Details

The spyware uses a multi-stage delivery mechanism: first, a dropper app requests accessibility permissions; then it downloads a second-stage payload that evades Google Play Protect. The final payload exfiltrates SMS messages, call logs, and device location. The campaign primarily targeted Bahrain, with secondary infections in Saudi Arabia and the UAE.

Exploitation of Crisis

The attackers timed the campaign to coincide with Iranian missile strikes on Israel in April 2024, which triggered civilian fear in Gulf states. Fake social media posts urged users to install the 'Bahrain Alert' app for missile warnings. The app was never available on official Google Play, relying entirely on sideloading via phishing links.

What's Next

Google has not commented on the takedown of the fake sites. It remains unclear whether the spyware is linked to a known state actor or criminal group.

1 source

Fake Bahrain alert app installs Android spyware via phony Google Play sites