Bahamut uses fake chat app to steal data

August 2, 2023

CYFIRMA researchers have warned that an Indian APT hacking group ‘Bahamut’ is using a fake Android app called “SafeChat” to infect devices with spyware malware that steals call logs, texts, and GPS locations from phones.

The Android spyware is suspected to be a variant of “Coverlm,” which steals data from communication apps such as Telegram, Signal, WhatsApp, Viber, and Facebook Messenger. And the attack is conducted mainly through spear phishing messages on WhatsApp that send the malicious payloads directly to the victim.

Safe Chat features a deceiving interface that makes it appear as a real chat app and also takes the victim through a seemingly legitimate user registration process that adds credibility and serves as an excellent cover for the spyware. It then acquires permissions to use the Accessibility Services, which are subsequently abused to automatically grant the spyware more permissions.

These additional permissions enable the spyware to access to the victim’s contacts list, SMS, call logs, external device storage, and fetch precise GPS location data from the infected device. The app also requests the user to approve exclusion from Android’s battery optimization subsystem, which terminates background processes when the user isn’t actively engaging with the app.

A dedicated data exfiltration module transfers information from the device to the attacker’s C2 server through port 2053. The stolen data is encrypted using another module that supports RSA, ECB, and OAEPPadding. At the same time, the attackers also use a “letsencrypt” certificate to evade any network data interception efforts against them.

CYFIRMA concludes the report by saying that it holds enough evidence to link Bahamut to working on behalf of a specific state government in India.

The sources for this piece include an article in BleepingComputer.

Top Stories

Related Articles

October 27, 2025 ESET researchers say North Korea’s Lazarus hacking group has launched a new wave of cyberattacks on defence more...

October 18, 2025 Public announcement systems at several airports in Canada and the United States were hijacked this week to more...

October 16, 2025 Canadian Tire Corp. Ltd. says a data breach in its e-commerce system exposed personal information from customers more...

October 7, 2025 LinkedIn has filed a federal lawsuit accusing a data-scraping company of creating more than a million fake more...

Jim Love

Jim is an author and podcast host with over 40 years in technology.

Share:
Facebook
Twitter
LinkedIn