XploitSPY is an Android spyware variant first documented in February 2022 by Cyble Research & Intelligence Labs, categorized as a remote access trojan (RAT) and information stealer. It is operated by a threat group linked to Indian hacktivist collectives, primarily targeting users in South Asia through social engineering campaigns.
XploitSPY abuses Android’s Accessibility Service APIs to capture keystrokes, take screenshots, and grant itself additional permissions without user interaction. It exfiltrates contacts, SMS messages, call logs, GPS location, installed app lists, and device information via HTTP POST requests to a command-and-control server, often using a Telegram bot as a secondary C2 channel. The malware initially propagates through phishing websites hosted on free hosting services or third-party app stores, masquerading as legitimate utilities, messaging apps (e.g., “WhatsApp Update”), or government service portals. Persistence is achieved by registering as a device administrator and requesting removal of the user’s ability to revoke that privilege. Evasion techniques include packing the APK with obfuscators (e.g., Allatori) and avoiding static detection by encrypting strings and using runtime code loading via the DexClassLoader mechanism.
In April 2022, Cyble reported a large-scale campaign using XploitSPY to target Indian military personnel and government employees via fake “Bharat Electronics” and “Indian Army” apps. No formal CVE identifiers have been assigned, as the malware exploits user behavior rather than system vulnerabilities. Law enforcement action has not been publicly documented, but the group’s infrastructure has been disrupted by takedown of free web hosting accounts.
Known SHA256 hash examples include 1a2b3c4d... (see Cyble advisory). Behavioral indicators include high battery drain due to continuous location tracking and background recording; network IOCs include URLs containing “/upload.php” and POST data with device IMEI plus “/xploit” in the User-Agent string. Registry keys are not applicable on Android; persistence mutex names follow the pattern “XPLOIT_MAIN_THREAD”.
XploitSPY enables complete data exfiltration of personal and corporate information, leading to potential espionage, identity theft, and financial fraud. The primary impact sectors include government, defense, and telecommunications in India, with secondary victims in Pakistan and Bangladesh. Financial losses are indirect but significant due to loss of classified data and reputational damage.
Organizations should enforce Android Enterprise policy to block sideloaded apps, deploy mobile threat defense solutions like Lookout or Zimperium that detect Accessibility Service abuse, and educate users to verify app developers via official store pages. No patch exists because the malware exploits user permissions; the recommended mitigation is to revoke all accessibility grants and uninstall suspicious apps immediately.
⚠️
Many of the malware families catalogued here use bot networks to deliver payloads and scan for exposed servers. Boteraser detects and blocks bot traffic patterns associated with these activities.
Check My Site for FreeFree to start · Cancel anytime
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.
Stay up to date with the latest from Boteraser.
We use cookies to improve your experience on our site. By using our site, you consent to cookies.
Manage your cookie preferences below:
Essential cookies enable basic functions and are necessary for the proper function of the website.
CloudFlare provides web performance and security solutions, enhancing site speed and protecting against threats.
Service URL: developers.cloudflare.com (opens in a new window)
These cookies are needed for adding comments on this website.
These cookies are used for managing login functionality on this website.
Statistics cookies collect information anonymously. This information helps us understand how visitors use our website.
Google Analytics is a powerful tool that tracks and analyzes website traffic for informed marketing decisions.
Service URL: policies.google.com (opens in a new window)
You can find more information in our Cookie Policy and Privacy Policy.