In May 2018, we discovered a campaign targeting dozens of mobile Android devices belonging to Israeli citizens. Kaspersky spyware sensors caught the signal of an attack from the device of one of the victims; and a hash of the APK involved (Android application) was tagged in our sample feed for inspection. Once we looked into the file, we quickly found out that the inner-workings of the APK included a malicious payload, embedded in the original code of the application. This was an original spyware program, designed to exfiltrate almost all accessible information. During the course of our research, we noticed that we were not the only ones to have found the operation. Researchers from Bitdefender also released an analysis of one of the samples in a blogpost. Although something had already been published, we decided to do something different with the data we acquired. The following month, we released a private report on our Threat Intelligence Portal to alert our clients about this newly discovered operation and began writing YARA rules in order to catch more samples. We decided to call the operation “ViceLeaker”, because of strings and variables in its code.
Executive Summary
ViceLeaker is a mobile-focused threat actor identified in May 2018 targeting Android users in Israel. The group uses sophisticated mobile spyware embedded in malicious APK files to exfiltrate sensitive information, likely for surveillance or espionage purposes.
Goals & Targeting
ViceLeaker appears to target individuals or organizations likely of interest for surveillance, with a particular focus on Israeli citizens during initial sightings. Their strategic goal may involve gathering sensitive data or conducting espionage activities against high-value targets in specific regions. The limited but targeted campaign suggests a focus on discrete operations rather than large-scale disruption.
Enhanced Description
In May 2018, Kaspersky discovered a mobile spyware campaign targeting Android devices of Israeli citizens. The attack involved a malicious payload embedded within an otherwise legitimate application's code, highlighting ViceLeaker's ability to deliver sophisticated malware through seemingly innocuous vectors. Both Kaspersky and Bitdefender reported on the campaign, with Kaspersky naming it "ViceLeaker" due to specific strings found in its code. The operation was initially low-key but gained attention through private threat intelligence reports released by Kaspersky. ViceLeaker's ability to embed malicious code within legitimate applications underscores their technical capabilities and targeting focus on mobile users in specific geographies.
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
ViceLeaker's campaign was initially limited to targeting Android users in Israel, suggesting a geographically focused approach. The use of private threat intelligence reports and YARA rules indicates an effort to contain the threat and prevent widespread dissemination of their tools. Notable for its targeting precision, ViceLeaker remains a potentially serious threat to individual privacy and national security interests.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
High confidence in the identification of ViceLeaker due to multiple independent detections by reputable security firms, though limited public reporting leaves some operational details speculative. Additional data would clarify ViceLeaker's long-term goals and potential association with larger threat groups.
No techniques linked yet.
No tools linked yet.
No campaigns linked yet.
No observed data linked yet.
No IOCs linked yet.
No references recorded yet.
0
Techniques
0
Tools
0
Campaigns
0
IOCs
0
Observed Data
0
Tactics