Lookout Links MENA Civil Society Espionage Campaign to BITTER-Associated Hack-for-Hire Operation

· Original article ↗

Summary

Lookout and Access Now describe a campaign targeting Middle Eastern civil society members since at least 2022, using spearphishing, credential theft and Android spyware called ProSpy. Lookout assesses links to BITTER with moderate confidence.

Key points

  • The campaign has operated since at least 2022, targeting journalists, opposition politicians and other civil society members in the Middle East; government officials may also have been targeted.
  • Attackers used persistent social engineering through fake social-media personas and messaging apps to deliver spearphishing links, steal credentials or direct Android users to install spyware.
  • ProSpy disguises itself as Signal, ToTok or Botim and can collect contacts, SMS, device details, files and application backups, then exfiltrate them on command from its C2 server.
  • iOS-focused phishing impersonated iCloud and targeted encrypted-messaging accounts, including Signal, where victims could be tricked into linking an attacker-controlled device.
  • Lookout found similarities between ProSpy and BITTER’s Dracarys malware and infrastructure, but says attribution is moderately confident and cannot determine whether BITTER or an associated hack-for-hire group conducted the operation.
  • Researchers identified hundreds of phishing domains and multiple ProSpy distribution and C2 domains; the report lists file hashes and domains as indicators of compromise.

Article Details

Attack Vectors
  • Sockpuppet personas contact targets through social media, networking apps and messaging applications, then pressure them to open spearphishing links.
  • Phishing pages impersonate communication services and other organizations to seek credentials; iOS targets were observed receiving links impersonating iCloud.
  • A Signal-linked-device QR code lure attempts to induce victims to link their accounts to a device accessible to the threat actor.
  • Android targets are directed to sites impersonating messaging applications, where malicious ProSpy APK files may download automatically.
Defensive Notes
  • Lookout encourages organizations, particularly at-risk civil society members, to remain aware of mobile malware and related espionage threats.

Indicators of compromise

TypeIndicatorContext
DOMAINbotim-app[.]proProSpy staging and distribution site using a Botim lure.
DOMAINclubline[.]ccListed among C2 servers used by ProSpy samples.
DOMAINcom-ae[.]netDomain described as used to distribute ProSpy and linked by a third-party infrastructure finding to BITTER APT activity.
DOMAINencryption-plug-in-signal[.]com-ae[.]netProSpy distribution host using a Signal lure.
DOMAINicrosoft-acco[.]unt-log[.]comExample phishing domain attributed in the article to an earlier Rebsec operation.
DOMAINregularsports[.]orgListed in the article’s ProSpy C2 domain indicators.
DOMAINrelaxmode[.]orgListed ProSpy C2 domain.
DOMAINsgnlapp[.]infoListed ProSpy C2 domain.
DOMAINtotok-pro[.]aeProSpy distribution host using a ToTok lure.
DOMAINtotok-pro[.]ai-ae[.]ioProSpy staging and distribution host using a ToTok lure.
DOMAINtotok-pro[.]ioListed ProSpy C2 domain and ToTok-lure distribution host.
DOMAINtotokapp[.]infoListed ProSpy C2 domain.
DOMAINtrack-portal[.]coListed ProSpy C2 domain.
DOMAINtreasuresland[.]ccListed ProSpy C2 domain.
DOMAINyoutubepremiumapp[.]comC2 domain reportedly used by Dracarys Android malware in 2022.
SHA102ee423f1cd1a123169ef1e4e7d40dbb2139d86bProSpy sample listed as Botim Pro.
SHA1154d67f871ffa19dce1a7646d5ae4ff00c509ee4ProSpy sample listed as Signal Encryption Plugin.
SHA126fa78ccf9dbe970a4bc2911592ec99db809ffe5ProSpy sample listed as Signal Encryption Plugin.
SHA138174544c6d6e127bbfee0bab031c2370e0a1becProSpy sample listed as Signal Encryption Plugin.
SHA143f4dc193503947cb9449fe1cca8d3feb413a52dProSpy sample listed as ToTok Pro.
SHA150c7cab6221b24636f0d053679b843a194d8f4a1ProSpy sample listed as Signal Encryption Plugin.
SHA1579f9e5db2befccb61c833b355733c24524457abProSpy sample listed as ToTok Pro.
SHA16339add91eb118831571e30801a28a40b2c304a0ProSpy sample listed as ToTok Pro.
SHA18152b06537853e90103ed956653e446453e80293ProSpy sample listed as ToTok Pro.
SHA192dd37a709cbc7379e2804fe63d61a7d9846f934ProSpy sample listed as Botim Pro.
SHA1ae60794c6f1d4893a20009437ebf96d790985a7cProSpy sample listed as ToTok Pro.
SHA1af7ab9213eaa20a6b1a4fb5be6e6b2e56160c746ProSpy sample listed as Botim Pro.
SHA1bebd8af44329037c34c1d5812ada26bc2230f50dProSpy sample listed as ToTok Pro.
SHA1ffaac2fdd9b6f5340d4202227b0b13e09f6ed031ProSpy sample listed as ToTok Pro.
URLhxxps[:]//botim-app[.]pro/botim_s_v3[.]9[.]2[.]apkURL that automatically downloads a malicious ProSpy APK from the Botim-lure site.
URLhxxps[:]//join-secure-call[.]ai-ae[.]ioVideo-call lure URL that leads targets toward a ProSpy distribution page.
URLhxxps[:]//totok-pro[.]ai-ae[.]io/ca9bCVSI[.]phpRedirect URL leading to a ToTok-lure ProSpy distribution page.
URLhxxps[:]//totok-pro[.]ai-ae[.]io/totok-release_v1[.]9[.]13[.]457_signed_14_12_25[.]apkURL that automatically downloads a malicious ProSpy APK.

MITRE ATT&CK

Threat Actors

Malware

Products

Androidas other civil society members in the region. During the course of the investigation, they discovered Android malware tied to the phishing infrastructure. Lookout’s analysis of the phishing infrastructure andBotimin this report as ProSpy. ProSpy masquerades as secure messaging applications like Signal, ToTok and Botim to lure victims. ProSpy has many common spyware features to exfiltrate sensitive data like contacts, SMSiCloudOur observations indicate that victims using iOS devices are targeted via phishing links impersonating iCloud, likely in an attempt to access backups of their mobile devices, in addition to specific targeting of E2EEiMessagesocial media and networking apps like LinkedIn, or directly through communication applications such as iMessage posing as Apple Support. Targets are then pressured to click on a spearphishing link, which eitheriOSOur observations indicate that victims using iOS devices are targeted via phishing links impersonating iCloud, likely in an attempt to access backups of their mobile devices, in addition to specific targeting of E2EELinkedInTargets are contacted by malicious sockpuppet personas through social media and networking apps like LinkedIn, or directly through communication applications such as iMessage posing as Apple Support. Targets areSignalboth of these families in this report as ProSpy. ProSpy masquerades as secure messaging applications like Signal, ToTok and Botim to lure victims. ProSpy has many common spyware features to exfiltrate sensitive dataToTokthese families in this report as ProSpy. ProSpy masquerades as secure messaging applications like Signal, ToTok and Botim to lure victims. ProSpy has many common spyware features to exfiltrate sensitive data like

Countries

BahrainBahrain - Ministry of Foreign AffairsBangladeshtelecommunications and government entities, such as Ministries of Foreign Affairs, in China, Pakistan, Bangladesh, Saudi Arabia, Turkey and further abroad in rare cases.Chinamilitary, energy, telecommunications and government entities, such as Ministries of Foreign Affairs, in China, Pakistan, Bangladesh, Saudi Arabia, Turkey and further abroad in rare cases.Egyptcontacted to investigate phishing attacks targeting prominent journalists and opposition politicians in Egypt, as well as other civil society members in the region. During the course of the investigation, theyIndiaLebanonidentified the targeting of civil society members in the Middle East, including victims in Egypt and Lebanon. Based on the phishing domains observed and ProSpy malware lures, we believe that this campaign alsoPakistanenergy, telecommunications and government entities, such as Ministries of Foreign Affairs, in China, Pakistan, Bangladesh, Saudi Arabia, Turkey and further abroad in rare cases.Saudi Arabiabelieve that this campaign also likely targeted victims in Bahrain, Bahraini government entities, UAE, Saudi Arabia, the United Kingdom, Egyptian government entities, and potentially the United States or alumni of USTurkeygovernment entities, such as Ministries of Foreign Affairs, in China, Pakistan, Bangladesh, Saudi Arabia, Turkey and further abroad in rare cases.United Arab Emiratesa blog about two Android spywares they named ProSpy and ToSpy which targeted users in the United Arab Emirates. These malware families were used in the targeting of civil society in the campaign identified byUnited Kingdomalso likely targeted victims in Bahrain, Bahraini government entities, UAE, Saudi Arabia, the United Kingdom, Egyptian government entities, and potentially the United States or alumni of US universities. A listUnited Statesentities, UAE, Saudi Arabia, the United Kingdom, Egyptian government entities, and potentially the United States or alumni of US universities. A list of IoCs at the time of writing is appended at the end of this

Industries

Related Articles