VajraSpy is an advanced Android remote access trojan (RAT) first documented in January 2024 by the ThreatFabric research team. It belongs to the category of espionage malware and is attributed to the Patchwork APT group (also known as Dropping Elephant) which operates from India. The malware specifically targets individuals in Pakistan, focusing on government and military personnel for intelligence gathering.
VajraSpy propagates through malicious WhatsApp and Telegram messaging apps distributed via third-party stores and phishing links. Once installed, it abuses Android accessibility services to grant itself extensive permissions without user interaction. Its capabilities include keylogging, call recording, contact exfiltration, SMS theft, and capturing real-time device location. The malware communicates with its C2 infrastructure over HTTPS using encrypted JSON payloads to evade detection. Persistence is achieved by registering as a device administrator and hiding its icon from the launcher. Evasion techniques include checking for emulator environments and refusing to run on rooted devices.
VajraSpy first appeared in early 2023 in low-volume campaigns targeting Pakistani Android users. In December 2023, ThreatFabric identified a cluster of malicious apps on Google Play that were later removed. No specific CVEs are associated as the malware exploits user permissions rather than system vulnerabilities. As of early 2024, no law enforcement actions have been publicly reported against the operators.
Known APK package names include com.secure.wechat and com.aim.message. The malware connects to C2 domains such as api-vajra[.]com and cloud-check[.]xyz. Behavioral signatures include requests for AccessibilityService permissions and persistent background service names like VajraService. Network traffic exhibits POST requests to endpoints such as /update.php with device information encoded in JSON.
VajraSpy enables complete device compromise by an APT actor, leading to exfiltration of sensitive communications, contact lists, and location data. The primary impact is intelligence theft against Pakistani government and military personnel. No financial losses have been publicly documented, but the espionage value to the threat actor is considered high.
Defenders should deploy EDR solutions that monitor for accessibility service abuse and block installation of apps from unknown sources. Organizations should enforce application whitelisting and conduct user awareness training against social engineering lures. ThreatFabric has published YARA rules and Suricata signatures for detection.
Free Threat Visibility
Boteraser's behavioral analysis identifies bot traffic patterns — giving you insight into automated activity that may be scanning or probing your web infrastructure.
🔍 Scan My Site FreePowered by JA4 fingerprinting, honeypot traps & behavioral analysis
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.
Stay up to date with the latest from Boteraser.
We use cookies to improve your experience on our site. By using our site, you consent to cookies.
Manage your cookie preferences below:
Essential cookies enable basic functions and are necessary for the proper function of the website.
CloudFlare provides web performance and security solutions, enhancing site speed and protecting against threats.
Service URL: developers.cloudflare.com (opens in a new window)
These cookies are needed for adding comments on this website.
These cookies are used for managing login functionality on this website.
Statistics cookies collect information anonymously. This information helps us understand how visitors use our website.
Google Analytics is a powerful tool that tracks and analyzes website traffic for informed marketing decisions.
Service URL: policies.google.com (opens in a new window)
You can find more information in our Cookie Policy and Privacy Policy.