Lookout reported multiple mobile surveillance campaigns targeting officials, diplomats, military personnel, activists, and other high-value individuals across South Asia and the Middle East. In one campaign, the Confucius APT was linked with high confidence to the Android spyware families Hornbill and SunBird, which targeted people connected to Pakistan’s military and nuclear organizations as well as election officials in Kashmir. The malware could exfiltrate messages, geolocation, media, call records, documents, and WhatsApp content, while insecure command-and-control servers exposed more than 18 GB of stolen data tied to victims in India, Pakistan, Kazakhstan, Europe, the United States, and the UAE.
Lookout also detailed the earlier Stealth Mango and Tangelo surveillance operation, attributed to members of the Pakistani military, which targeted Android and iOS devices used by government officials, diplomats, military personnel, and activists in Pakistan, Afghanistan, India, Iraq, and the UAE. That campaign relied mainly on phishing through fake Facebook personas and, in some cases, physical access rather than exploits, and collected government communications, travel details, identity documents, GPS data, legal and medical records, and photos from sensitive meetings. Lookout said Google updated Google Play Protect and removed malicious Android apps from affected devices, while the research also tied the operators to freelance developers associated with other commercial or commodity spyware tools.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
11 events from the most recent confirmed update back to the earliest known activity.
Lookout identified the newest Hornbill sample in December 2020 and assessed that Hornbill was still actively deployed at that time.
Lookout observed SunBird exfiltration activity resume on 11 April 2019, the same day the 2019 Indian general elections began.
Lookout stated that Retina-X Studios shut down MobileSpy and other surveillance products in May 2018 after being hacked twice.
Lookout first observed the Hornbill Android surveillanceware family in May 2018. Lookout later assessed Hornbill was derived from the MobileSpy code base.
Lookout stated that Confucius had previously used Android malware named ChatSpy starting in 2017.
Lookout first observed the SunBird Android surveillanceware family in January 2017. The malware was later linked with high confidence to Confucius APT.
Lookout said the pro-India Confucius APT had primarily targeted Pakistani and other South Asian entities since at least 2013.
Lookout reported two Android surveillanceware families, Hornbill and SunBird, and assessed with high confidence that they were used by the Confucius APT. The report said the malware targeted people linked to Pakistan's military and nuclear organizations as well as election officials in Kashmir.
Lookout analyzed more than 18 GB of publicly exposed exfiltrated data from at least six insecurely configured SunBird C2 servers. A newly analyzed dataset contained 156 victims, including targets in India, Pakistan, Kazakhstan, Europe, the United States, and the UAE.
After Lookout alerted Google to Stealth Mango, Google said the malicious apps were not on Google Play, updated Google Play Protect to protect users, and began removing the apps from affected devices.
Lookout Security Intelligence uncovered the Stealth Mango Android and Tangelo iOS surveillanceware families targeting officials, diplomats, military personnel, and activists across Pakistan, Afghanistan, India, Iraq, and the UAE. Lookout assessed the campaign was likely run by members of the Pakistani military.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
3 references tracked. Mallory keeps watching after this page renders.
blog.lookout.com
Open sourcelookout.com
Open sourcelookout.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.