Summary: Cybersecurity researchers have identified a campaign targeting Russian military personnel, distributing Android spyware disguised as the Alpine Quest mapping software. The malicious app collects sensitive data and allows for further exploitation via downloadable modules. Additionally, Kaspersky reports that Russian organizations in various sectors have been targeted by a backdoor disguised as an update for a secure networking software called ViPNet.
Affected: Russian military personnel, Russian organizations in government, finance, and industrial sectors
Keypoints :
- Android spyware, named Android.Spy.1292.origin, is concealed within modified versions of Alpine Quest mapping software.
- The trojan collects sensitive information including phone numbers, contact lists, and geolocation data, and communicates with a Telegram bot.
- A sophisticated backdoor targeting ViPNet updates allows attackers to steal files and execute further malicious tasks on infected systems.
Source: https://thehackernews.com/2025/04/android-spyware-disguised-as-alpine.html