PJobRAT Used Against Indian Military Personnel

PJobRAT, a Remote Access Trojan (RAT,) was recently seen being used in an ongoing campaign against Indian military personnel. The highly targeted attack has been active since January, and the criminals are abusing fake dating applications to deliver the dangerous PJobRAT to the Android devices of military personnel. The criminals are distributing the laced APK file via online forums, social media posts, and other Web-based content frequented by the Indian military.

Fake Dating Apps Used to Propagate This Sneaky Trojan

Some of the files laced with the PJobRAT are copies of legitimate apps, while others have been made up by the criminals. Rita, Ponam, SignalLite, HangOn, and Trendbanter are the names of some of the malicious Android apps. Once planted, the PJobRAT will take over the compromised device by abusing the 'accessibility' permissions of Android. Its operators will get the ability to hijack images and video, record audio via the microphone, steal contacts, view text messages, and much more.

Once installed, the fake dating app will not use the icon or name it was advertised with – instead, it may steal the name and icon of a legitimate app like Google Chrome, WhatsApp, or something similar. This way, the victim might not be able to manually identify and remove the malicious app.

What is surprising about the PJobRAT is that it appears to be very poorly coded when it comes to security. Cybersecurity experts were able to identify the control server's IP address and discovered that all stolen data exfiltrated to it was stored in public directories, accessible by anyone with the IP address.

Android malware like PJobRAT has become common in the past decade and, unfortunately, the number of such threats is likely to grow exponentially in the near future. Take the necessary security measures to protect your data and privacy by securing your Android device with an up-to-date antivirus app.

June 22, 2021
Loading...

Cyclonis Backup Details & Terms

The Free Basic Cyclonis Backup plan gives you 2 GB of cloud storage space with full functionality! No credit card required. Need more storage space? Purchase a larger Cyclonis Backup plan today! To learn more about our policies and pricing, see Terms of Service, Privacy Policy, Discount Terms and Purchase Page. If you wish to uninstall the app, please visit the Uninstallation Instructions page.

Cyclonis Password Manager Details & Terms

FREE Trial: 30-Day One-Time Offer! No credit card required for Free Trial. Full functionality for the length of the Free Trial. (Full functionality after Free Trial requires subscription purchase.) To learn more about our policies and pricing, see EULA, Privacy Policy, Discount Terms and Purchase Page. If you wish to uninstall the app, please visit the Uninstallation Instructions page.