ESET reported that an Android espionage operation dubbed eXotic Visit distributed trojanized but working mobile apps—primarily fake messaging services—to deliver the custom XploitSPY malware. The campaign was active from at least late 2021 through the end of 2023 and spread through dedicated websites, GitHub, alternative app stores, and Google Play. Researchers said the activity appears to have mainly targeted users in Pakistan and India, and they track the operators as Virtual Invaders without a confirmed link to any previously known threat group.
The malware gave operators broad surveillance and remote-control access, including theft of contacts, SMS messages, call logs, files, location data, notifications, audio recordings, and photos. ESET said later variants improved stealth with obfuscation, emulator detection, Firebase-based command-and-control retrieval, and native libraries used to conceal C2 details. The company identified about 380 compromised accounts across some of the malicious apps and reported multiple samples to Google, which removed the affected apps from Google Play.

Pull IOCs and campaign context straight into your stack.
8 events from the most recent confirmed update back to the earliest known activity.
The Defcom app was uploaded to Google Play using a new C2 domain, zee.xylonn[.]com, and reached about six installs before removal.
ESET reported that the eXotic Visit espionage campaign continued operating through the end of 2023 as the malware evolved with added obfuscation, emulator detection, Firebase-based C2 retrieval, and native code.
The Sim Info app was uploaded to Google Play carrying the same malicious code as other campaign samples along with a native library to conceal sensitive data.
ESET found that version 1.3 of Dink Messenger, uploaded to Google Play, introduced the campaign's malicious code while retaining the same developer signing certificate as earlier benign versions.
The Dink Messenger app was first uploaded to Google Play without malicious functionality before later being weaponized.
MalwareHunterTeam publicly shared indicators related to the WeTalk lure, one of the earliest identified samples in the campaign.
ESET said the Android espionage campaign it calls eXotic Visit was active from at least November 2021, using trojanized but functional apps to target victims.
ESET identified ten additional Google Play apps containing XploitSPY-based code and reported multiple malicious apps to Google, which removed all identified malicious apps from Google Play.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 11 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Pull the IOCs, campaigns, and victimology behind this family, ready to push into your SIEM and EDR.
1 reference tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.