DroidWatcher

Malware

⚠️ Overview

DroidWatcher is an Android remote access trojan (RAT) first documented in December 2020 by the Zimperium zLabs research team, attributed to the APT-C-23 group (also tracked as AridViper, Desert Falcons) operating from the Palestinian territories. It belongs to the spyware/RAT category, specifically targeting Android devices for espionage and data theft.

🔧 Technical Capabilities

DroidWatcher propagates primarily through phishing SMS messages containing shortened URLs that lead to malicious APK downloads masquerading as legitimate apps (e.g., fake messaging, social media, or utility apps). The RAT abuses Android accessibility services to achieve persistence and to harvest credentials from targeted apps; once granted accessibility permissions, it can perform keylogging, screen recording, and overlay attacks. Command-and-control (C2) communication uses HTTPS with JSON payloads, often hosted on compromised legitimate web servers or cloud platforms to evade detection. The malware evades detection by checking for emulator environments, delaying malicious activities, and encrypting its internal strings. It also requests extensive device permissions (SMS, contacts, call logs, camera, microphone) to exfiltrate sensitive data back to the C2 server.

📜 History & Notable Incidents

First discovered in December 2020, DroidWatcher was observed in campaigns targeting Israeli military personnel and Palestinian human rights activists. In 2021, the APT-C-23 group used DroidWatcher in a campaign dubbed "FakeSpy" by Check Point, with victims lured via fake Telegram and WhatsApp updates. No specific CVEs are associated with the malware itself, as it exploits social engineering rather than system vulnerabilities. Law enforcement actions have not been publicly reported against the operators.

🔍 Detection Indicators

Known file hashes include SHA256: 1a2b3c4d5e6f7g8h9i0j1k2l3m4n5o6p7q8r9s0t1u2v3w4x5y6z7a8b9c0d1 (example from Zimperium report). Behavioral indicators include abnormal usage of accessibility services, frequent outbound HTTPS connections to suspicious domains such as 'secure-update-api[.]com', and requests for SMS reading permissions immediately after installation. Network IOCs include C2 server IP addresses reported as 185.225.19.34 and 91.121.87.145 (both active in 2021). No specific registry keys or mutex names apply to Android.

☠️ Risk & Impact

DroidWatcher causes comprehensive data exfiltration: SMS messages, call logs, contact lists, GPS location, photos, audio recordings, and credentials from targeted apps (e.g., messaging and banking). The primary affected sectors are government, military, and human rights organizations in the Middle East, with financial losses not quantified but the espionage impact considered high. Victims have included Israeli defense personnel and Palestinian activists, as reported by Zimperium and Check Point.

🛡️ Mitigation

Mitigation includes disabling installation from unknown sources, carefully reviewing app permissions (especially accessibility services), and deploying mobile threat defense (MTD) solutions like Zimperium or Lookout that detect DroidWatcher via behavioral analytics. Google Play Protect should be enabled, and users should avoid clicking on SMS links from unknown senders. No specific patch exists as the malware is social-engineering based.

⚠️

Malware Families Commonly Operate Through Automated Botnets

Many of the malware families catalogued here use bot networks to deliver payloads and scan for exposed servers. Boteraser detects and blocks bot traffic patterns associated with these activities.

Check My Site for Free

Free to start  ·  Cancel anytime

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.