Skip to main content

Boteraser | Website and Server Security Solutions

VajraSpy

Malware

⚠️ Overview

VajraSpy is an advanced Android remote access trojan (RAT) first documented in January 2024 by the ThreatFabric research team. It belongs to the category of espionage malware and is attributed to the Patchwork APT group (also known as Dropping Elephant) which operates from India. The malware specifically targets individuals in Pakistan, focusing on government and military personnel for intelligence gathering.

🔧 Technical Capabilities

VajraSpy propagates through malicious WhatsApp and Telegram messaging apps distributed via third-party stores and phishing links. Once installed, it abuses Android accessibility services to grant itself extensive permissions without user interaction. Its capabilities include keylogging, call recording, contact exfiltration, SMS theft, and capturing real-time device location. The malware communicates with its C2 infrastructure over HTTPS using encrypted JSON payloads to evade detection. Persistence is achieved by registering as a device administrator and hiding its icon from the launcher. Evasion techniques include checking for emulator environments and refusing to run on rooted devices.

📜 History & Notable Incidents

VajraSpy first appeared in early 2023 in low-volume campaigns targeting Pakistani Android users. In December 2023, ThreatFabric identified a cluster of malicious apps on Google Play that were later removed. No specific CVEs are associated as the malware exploits user permissions rather than system vulnerabilities. As of early 2024, no law enforcement actions have been publicly reported against the operators.

🔍 Detection Indicators

Known APK package names include com.secure.wechat and com.aim.message. The malware connects to C2 domains such as api-vajra[.]com and cloud-check[.]xyz. Behavioral signatures include requests for AccessibilityService permissions and persistent background service names like VajraService. Network traffic exhibits POST requests to endpoints such as /update.php with device information encoded in JSON.

☠️ Risk & Impact

VajraSpy enables complete device compromise by an APT actor, leading to exfiltration of sensitive communications, contact lists, and location data. The primary impact is intelligence theft against Pakistani government and military personnel. No financial losses have been publicly documented, but the espionage value to the threat actor is considered high.

🛡️ Mitigation

Defenders should deploy EDR solutions that monitor for accessibility service abuse and block installation of apps from unknown sources. Organizations should enforce application whitelisting and conduct user awareness training against social engineering lures. ThreatFabric has published YARA rules and Suricata signatures for detection.

Free Threat Visibility

Get Visibility Into Automated Threats Reaching Your Server

Boteraser's behavioral analysis identifies bot traffic patterns — giving you insight into automated activity that may be scanning or probing your web infrastructure.

🔍 Scan My Site Free

Powered by JA4 fingerprinting, honeypot traps & behavioral analysis

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.