The Bahamut cybermercenary group ran a targeted Android espionage campaign that distributed spyware through a fake SecureVPN website, using trojanized versions of legitimate VPN applications to infect victims. Researchers said the operation had been active since at least January 2022 and initially repackaged SoftVPN before later shifting to OpenVPN, embedding Bahamut spyware while gating execution with an activation-key mechanism that likely restricted infections to selected targets.
The malware was built for covert surveillance and data theft, with capabilities to collect contacts, SMS messages, call logs, location data, device details, installed-app lists, and files, as well as record phone calls. It also abused Android accessibility services to monitor messaging apps and enable keylogging. Investigators identified at least eight malware variants and linked the fake VPN infrastructure to earlier Bahamut activity through code overlap and operational similarities with prior SecureChat campaigns, reinforcing the assessment that the operation was low-volume, highly targeted, and designed for espionage rather than mass distribution.

TTPs, infrastructure, and targeting history in one profile.
5 events from the most recent confirmed update back to the earliest known activity.
ESET listed ft8hua063okwfdcu21pw[.]de at 104.21.10[.]79 as a command-and-control server associated with the campaign. The server was first seen on this date.
The first analyzed fake SecureVPN sample was uploaded to VirusTotal from an IP address geolocating to Singapore. This provided an early public artifact of the campaign's malware.
The domain thesecurevpn[.]com, used to distribute Bahamut's trojanized Android VPN apps, was registered. ESET later tied this infrastructure to the targeted spyware campaign.
ESET reported that Bahamut's Android espionage campaign had been running since at least January 2022. The operation used fake SecureVPN-branded apps to target victims with spyware.
ESET publicly described an active, highly targeted Android spyware campaign attributed to the Bahamut APT group. The report said the attackers distributed trojanized SoftVPN and OpenVPN apps via a fake SecureVPN website and identified at least eight malware versions.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 14 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See this adversary's TTPs, infrastructure, and targeting history, correlated against your exposure.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.