Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Instead, the application installed previously undocumented Android spyware that researchers named SafeLoveStealer. According to the report, the malware can steal photographs, videos, documents, location data and other information from infected devices while also allowing attackers to remotely activate the target’s microphone and record conversations.
5 distinct techniques documented for this family, organized by ATT&CK tactic.
После установления доверительных отношений с жертвами, им отправляли ссылки на якобы безопасные сервисы обмена фотографиями, облачные хранилища или формы для получения гуманитарной помощи.
The hackers impersonated women seeking romantic relationships or volunteers offering humanitarian assistance to initiate conversations with servicemen on Telegram and other messaging platforms before persuading them to download malicious applications or enter their Telegram credentials on spoofed websites.
Victims were tricked into clicking malicious links under various pretexts. In some cases, the attackers claimed to have developed a new application and asked users to test it. In others, they proposed exchanging intimate photographs through what appeared to be a secure photo-sharing application. Instead, the application installed previously undocumented Android spyware that researchers named SafeLoveStealer.
According to the report, the malware can steal photographs, videos, documents, location data and other information from infected devices... In addition to mobile spyware, the group deployed previously undocumented malware for desktop computers, dubbed SiribGrabber, whose primary purpose is to steal files from infected systems.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Previously undocumented Android spyware used in a romance-lure espionage campaign against Russian military personnel. It steals files and device data, including photos, videos, documents and location information, and can remotely activate the microphone to record conversations.
Android spyware used in social-engineering campaigns. After installation it collects device information, network and Wi-Fi data, geolocation, photos, documents, video and audio files, and can record microphone audio and perform speech recognition for covert exfiltration to operators.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.