Lookout Links MENA Civil Society Espionage Campaign to BITTER-Associated Hack-for-Hire Operation

Summary
Lookout and Access Now describe a campaign targeting Middle Eastern civil society members since at least 2022, using spearphishing, credential theft and Android spyware called ProSpy. Lookout assesses links to BITTER with moderate confidence.
Key points
- The campaign has operated since at least 2022, targeting journalists, opposition politicians and other civil society members in the Middle East; government officials may also have been targeted.
- Attackers used persistent social engineering through fake social-media personas and messaging apps to deliver spearphishing links, steal credentials or direct Android users to install spyware.
- ProSpy disguises itself as Signal, ToTok or Botim and can collect contacts, SMS, device details, files and application backups, then exfiltrate them on command from its C2 server.
- iOS-focused phishing impersonated iCloud and targeted encrypted-messaging accounts, including Signal, where victims could be tricked into linking an attacker-controlled device.
- Lookout found similarities between ProSpy and BITTER’s Dracarys malware and infrastructure, but says attribution is moderately confident and cannot determine whether BITTER or an associated hack-for-hire group conducted the operation.
- Researchers identified hundreds of phishing domains and multiple ProSpy distribution and C2 domains; the report lists file hashes and domains as indicators of compromise.
Article Details
- Attack Vectors
- Sockpuppet personas contact targets through social media, networking apps and messaging applications, then pressure them to open spearphishing links.
- Phishing pages impersonate communication services and other organizations to seek credentials; iOS targets were observed receiving links impersonating iCloud.
- A Signal-linked-device QR code lure attempts to induce victims to link their accounts to a device accessible to the threat actor.
- Android targets are directed to sites impersonating messaging applications, where malicious ProSpy APK files may download automatically.
- Defensive Notes
- Lookout encourages organizations, particularly at-risk civil society members, to remain aware of mobile malware and related espionage threats.
Indicators of compromise
| Type | Indicator | Context |
|---|---|---|
| DOMAIN | botim-app[.]pro | ProSpy staging and distribution site using a Botim lure. |
| DOMAIN | clubline[.]cc | Listed among C2 servers used by ProSpy samples. |
| DOMAIN | com-ae[.]net | Domain described as used to distribute ProSpy and linked by a third-party infrastructure finding to BITTER APT activity. |
| DOMAIN | encryption-plug-in-signal[.]com-ae[.]net | ProSpy distribution host using a Signal lure. |
| DOMAIN | icrosoft-acco[.]unt-log[.]com | Example phishing domain attributed in the article to an earlier Rebsec operation. |
| DOMAIN | regularsports[.]org | Listed in the article’s ProSpy C2 domain indicators. |
| DOMAIN | relaxmode[.]org | Listed ProSpy C2 domain. |
| DOMAIN | sgnlapp[.]info | Listed ProSpy C2 domain. |
| DOMAIN | totok-pro[.]ae | ProSpy distribution host using a ToTok lure. |
| DOMAIN | totok-pro[.]ai-ae[.]io | ProSpy staging and distribution host using a ToTok lure. |
| DOMAIN | totok-pro[.]io | Listed ProSpy C2 domain and ToTok-lure distribution host. |
| DOMAIN | totokapp[.]info | Listed ProSpy C2 domain. |
| DOMAIN | track-portal[.]co | Listed ProSpy C2 domain. |
| DOMAIN | treasuresland[.]cc | Listed ProSpy C2 domain. |
| DOMAIN | youtubepremiumapp[.]com | C2 domain reportedly used by Dracarys Android malware in 2022. |
| SHA1 | 02ee423f1cd1a123169ef1e4e7d40dbb2139d86b | ProSpy sample listed as Botim Pro. |
| SHA1 | 154d67f871ffa19dce1a7646d5ae4ff00c509ee4 | ProSpy sample listed as Signal Encryption Plugin. |
| SHA1 | 26fa78ccf9dbe970a4bc2911592ec99db809ffe5 | ProSpy sample listed as Signal Encryption Plugin. |
| SHA1 | 38174544c6d6e127bbfee0bab031c2370e0a1bec | ProSpy sample listed as Signal Encryption Plugin. |
| SHA1 | 43f4dc193503947cb9449fe1cca8d3feb413a52d | ProSpy sample listed as ToTok Pro. |
| SHA1 | 50c7cab6221b24636f0d053679b843a194d8f4a1 | ProSpy sample listed as Signal Encryption Plugin. |
| SHA1 | 579f9e5db2befccb61c833b355733c24524457ab | ProSpy sample listed as ToTok Pro. |
| SHA1 | 6339add91eb118831571e30801a28a40b2c304a0 | ProSpy sample listed as ToTok Pro. |
| SHA1 | 8152b06537853e90103ed956653e446453e80293 | ProSpy sample listed as ToTok Pro. |
| SHA1 | 92dd37a709cbc7379e2804fe63d61a7d9846f934 | ProSpy sample listed as Botim Pro. |
| SHA1 | ae60794c6f1d4893a20009437ebf96d790985a7c | ProSpy sample listed as ToTok Pro. |
| SHA1 | af7ab9213eaa20a6b1a4fb5be6e6b2e56160c746 | ProSpy sample listed as Botim Pro. |
| SHA1 | bebd8af44329037c34c1d5812ada26bc2230f50d | ProSpy sample listed as ToTok Pro. |
| SHA1 | ffaac2fdd9b6f5340d4202227b0b13e09f6ed031 | ProSpy sample listed as ToTok Pro. |
| URL | hxxps[:]//botim-app[.]pro/botim_s_v3[.]9[.]2[.]apk | URL that automatically downloads a malicious ProSpy APK from the Botim-lure site. |
| URL | hxxps[:]//join-secure-call[.]ai-ae[.]io | Video-call lure URL that leads targets toward a ProSpy distribution page. |
| URL | hxxps[:]//totok-pro[.]ai-ae[.]io/ca9bCVSI[.]php | Redirect URL leading to a ToTok-lure ProSpy distribution page. |
| URL | hxxps[:]//totok-pro[.]ai-ae[.]io/totok-release_v1[.]9[.]13[.]457_signed_14_12_25[.]apk | URL that automatically downloads a malicious ProSpy APK. |
MITRE ATT&CK
T1005 · Data from Local SystemProSpy collects local documents, media, archives, application backup files and recently modified files for exfiltration.T1036 · MasqueradingProSpy masquerades as Signal, ToTok or Botim applications, while distribution sites imitate those applications.T1041 · Exfiltration Over C2 ChannelProSpy uploads collected files, contacts, SMS messages and device information through C2 server endpoints.T1071.001 · Web ProtocolsProSpy communicates with its C2 servers through web endpoints, including /v3/getType to check for commands.T1083 · File and Directory DiscoveryProSpy traverses internal and external storage to find files by MIME type and searches filenames for backup files.T1098.005 · Device RegistrationA Signal QR-code phishing lure seeks to have victims link their accounts to another device, giving the threat actor access to Signal content.T1204.002 · Malicious FileAndroid targets are lured into obtaining a malicious APK presented as a messaging-application update.T1566.002 · Spearphishing LinkTargets are pressured to open spearphishing links sent through social or messaging applications, leading to credential phishing or ProSpy delivery.
Threat Actors
BahamutNamed as a hack-for-hire threat actor whose Android malware previously showed a limited overlap with BITTER’s BitterDawn; the article does not link Bahamut directly to the ProSpy operation.BITTER APTLookout assesses with moderate confidence that the operation has ties to BITTER APT, also identified in the article as T-APT-17; it does not establish whether BITTER conducted the operation itself.T-APT-17The article identifies T-APT-17 as BITTER APT, to which Lookout assesses the operation has ties with moderate confidence.
Malware
BitterDawnFor example, in 2020 we observed the same custom intent actions being used in BITTER’s Android malware BitterDawn and separate Android malware linked to the Bahamut threat actor, a known hack-for-hire group. ThisCorunaOver the past year, we’ve observed campaigns using top-tier malware like DarkSword, Coruna and Predator; stealthy tools which cost millions to develop. While these advanced kits indeed pose a threat to civil society andDarkSwordOver the past year, we’ve observed campaigns using top-tier malware like DarkSword, Coruna and Predator; stealthy tools which cost millions to develop. While these advanced kits indeed pose a threat to civil society andDracaryslinks “com-ae[.]net” domain to the domain “youtubepremiumapp[.]com”, which was a C2 domain used by the Dracarys Android malware in 2022. Dracarys was attributed to the BITTER APT group in 2022 by Meta.PredatorOver the past year, we’ve observed campaigns using top-tier malware like DarkSword, Coruna and Predator; stealthy tools which cost millions to develop. While these advanced kits indeed pose a threat to civil society andProSpyAndroid Surveillance: ProSpyToSpythe course of our investigation, ESET published a blog about two Android spywares they named ProSpy and ToSpy which targeted users in the United Arab Emirates. These malware families were used in the targeting of
Products
Androidas other civil society members in the region. During the course of the investigation, they discovered Android malware tied to the phishing infrastructure. Lookout’s analysis of the phishing infrastructure andBotimin this report as ProSpy. ProSpy masquerades as secure messaging applications like Signal, ToTok and Botim to lure victims. ProSpy has many common spyware features to exfiltrate sensitive data like contacts, SMSiCloudOur observations indicate that victims using iOS devices are targeted via phishing links impersonating iCloud, likely in an attempt to access backups of their mobile devices, in addition to specific targeting of E2EEiMessagesocial media and networking apps like LinkedIn, or directly through communication applications such as iMessage posing as Apple Support. Targets are then pressured to click on a spearphishing link, which eitheriOSOur observations indicate that victims using iOS devices are targeted via phishing links impersonating iCloud, likely in an attempt to access backups of their mobile devices, in addition to specific targeting of E2EELinkedInTargets are contacted by malicious sockpuppet personas through social media and networking apps like LinkedIn, or directly through communication applications such as iMessage posing as Apple Support. Targets areSignalboth of these families in this report as ProSpy. ProSpy masquerades as secure messaging applications like Signal, ToTok and Botim to lure victims. ProSpy has many common spyware features to exfiltrate sensitive dataToTokthese families in this report as ProSpy. ProSpy masquerades as secure messaging applications like Signal, ToTok and Botim to lure victims. ProSpy has many common spyware features to exfiltrate sensitive data like
Countries
BahrainBahrain - Ministry of Foreign AffairsBangladeshtelecommunications and government entities, such as Ministries of Foreign Affairs, in China, Pakistan, Bangladesh, Saudi Arabia, Turkey and further abroad in rare cases.Chinamilitary, energy, telecommunications and government entities, such as Ministries of Foreign Affairs, in China, Pakistan, Bangladesh, Saudi Arabia, Turkey and further abroad in rare cases.Egyptcontacted to investigate phishing attacks targeting prominent journalists and opposition politicians in Egypt, as well as other civil society members in the region. During the course of the investigation, theyIndiaLebanonidentified the targeting of civil society members in the Middle East, including victims in Egypt and Lebanon. Based on the phishing domains observed and ProSpy malware lures, we believe that this campaign alsoPakistanenergy, telecommunications and government entities, such as Ministries of Foreign Affairs, in China, Pakistan, Bangladesh, Saudi Arabia, Turkey and further abroad in rare cases.Saudi Arabiabelieve that this campaign also likely targeted victims in Bahrain, Bahraini government entities, UAE, Saudi Arabia, the United Kingdom, Egyptian government entities, and potentially the United States or alumni of USTurkeygovernment entities, such as Ministries of Foreign Affairs, in China, Pakistan, Bangladesh, Saudi Arabia, Turkey and further abroad in rare cases.United Arab Emiratesa blog about two Android spywares they named ProSpy and ToSpy which targeted users in the United Arab Emirates. These malware families were used in the targeting of civil society in the campaign identified byUnited Kingdomalso likely targeted victims in Bahrain, Bahraini government entities, UAE, Saudi Arabia, the United Kingdom, Egyptian government entities, and potentially the United States or alumni of US universities. A listUnited Statesentities, UAE, Saudi Arabia, the United Kingdom, Egyptian government entities, and potentially the United States or alumni of US universities. A list of IoCs at the time of writing is appended at the end of this
Industries
Civil societystealthy tools which cost millions to develop. While these advanced kits indeed pose a threat to civil society and organizations, it’s important to remember that successful attacks can also use relatively simpleEnergygathering aligning with Indian government interests. BITTER has been observed targeting military, energy, telecommunications and government entities, such as Ministries of Foreign Affairs, in China, Pakistan,Governmentsince at least 2022 until present day primarily targeting civil society members and potentially government officials in the Middle East. The operation features a combination of targeted spearphishing deliveredJournalismMilitaryintelligence gathering aligning with Indian government interests. BITTER has been observed targeting military, energy, telecommunications and government entities, such as Ministries of Foreign Affairs, in China,Telecommunicationsaligning with Indian government interests. BITTER has been observed targeting military, energy, telecommunications and government entities, such as Ministries of Foreign Affairs, in China, Pakistan, Bangladesh,