Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors ViceLeaker

Description

In May 2018, we discovered a campaign targeting dozens of mobile Android devices belonging to Israeli citizens. Kaspersky spyware sensors caught the signal of an attack from the device of one of the victims; and a hash of the APK involved (Android application) was tagged in our sample feed for inspection. Once we looked into the file, we quickly found out that the inner-workings of the APK included a malicious payload, embedded in the original code of the application. This was an original spyware program, designed to exfiltrate almost all accessible information. During the course of our research, we noticed that we were not the only ones to have found the operation. Researchers from Bitdefender also released an analysis of one of the samples in a blogpost. Although something had already been published, we decided to do something different with the data we acquired. The following month, we released a private report on our Threat Intelligence Portal to alert our clients about this newly discovered operation and began writing YARA rules in order to catch more samples. We decided to call the operation “ViceLeaker”, because of strings and variables in its code.

AI Analysis

· 1 week ago

Executive Summary

ViceLeaker is a mobile-focused threat actor identified in May 2018 targeting Android users in Israel. The group uses sophisticated mobile spyware embedded in malicious APK files to exfiltrate sensitive information, likely for surveillance or espionage purposes.

Goals & Targeting

ViceLeaker appears to target individuals or organizations likely of interest for surveillance, with a particular focus on Israeli citizens during initial sightings. Their strategic goal may involve gathering sensitive data or conducting espionage activities against high-value targets in specific regions. The limited but targeted campaign suggests a focus on discrete operations rather than large-scale disruption.

Enhanced Description

In May 2018, Kaspersky discovered a mobile spyware campaign targeting Android devices of Israeli citizens. The attack involved a malicious payload embedded within an otherwise legitimate application's code, highlighting ViceLeaker's ability to deliver sophisticated malware through seemingly innocuous vectors. Both Kaspersky and Bitdefender reported on the campaign, with Kaspersky naming it "ViceLeaker" due to specific strings found in its code. The operation was initially low-key but gained attention through private threat intelligence reports released by Kaspersky. ViceLeaker's ability to embed malicious code within legitimate applications underscores their technical capabilities and targeting focus on mobile users in specific geographies.

Key Capabilities

  • Delivery of mobile spyware via malicious APKs
  • Embedding payloads within legitimate application code
  • Information exfiltration from compromised devices

MITRE ATT&CK Tactics

Exfiltration
Information Gathering
Persistence

ATT&CK Techniques

T1566.001 - Exfiltration Over Alternative Protocol
T1572.001 - Data Transfer to Cloud Account
T1185 - Use of Programming Scripting Language for Credential Access

Software / Tooling

ViceLeaker Malware
Custom Android Spyware

Campaigns & Victims

ViceLeaker's campaign was initially limited to targeting Android users in Israel, suggesting a geographically focused approach. The use of private threat intelligence reports and YARA rules indicates an effort to contain the threat and prevent widespread dissemination of their tools. Notable for its targeting precision, ViceLeaker remains a potentially serious threat to individual privacy and national security interests.

IOC Patterns

  • Android APKs with embedded malicious payloads
  • Network traffic originating from known ViceLeaker C2 servers
  • Spear-phishing attempts delivering malicious mobile apps

Recommended Actions

  • Monitor for Android applications linked to ViceLeaker hash signatures
  • Educate users on the risks of downloading unknown or suspicious apps
  • Implement YARA-based detection rules in SIEM solutions to identify VPSC-related threats
  • Enhance app store scanning to detect malicious updates

Suggested Tags

Mobile Threat
Surveillance Malware
Geographic Targeting (Israel)
Spyware

Confidence Assessment

High confidence in the identification of ViceLeaker due to multiple independent detections by reputable security firms, though limited public reporting leaves some operational details speculative. Additional data would clarify ViceLeaker's long-term goals and potential association with larger threat groups.

ATT&CK Techniques

No techniques linked yet.

Software / Tooling

No tools linked yet.

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

Indicators of Compromise

No IOCs linked yet.

References

No references recorded yet.

Intel Summary

0

Techniques

0

Tools

0

Campaigns

0

IOCs

0

Observed Data

0

Tactics

Tags

Critical Infrastructure
Mobile Threat
Surveillance Malware
Geographic Targeting (Israel)
Spyware

Details

Type
Unknown
Confidence
60%
Added
May 17, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.