Signal Plus Messenger

Malware updated 7 months ago (2024-05-04T20:08:44.546Z)
Download STIX
Preview STIX
Signal Plus Messenger and FlyGram are malware variants of a sophisticated espionage tool named BadBazaar, believed to be orchestrated by a China-linked threat actor known as Gref. These malicious applications were distributed through the Google Play store, Samsung Galaxy Store, and specific websites, imitating popular communication apps Signal and Telegram. The campaign has been ongoing since July 2023, targeting Android users. Both Signal Plus Messenger and FlyGram contain code to check if the device operator is Chinese, similar to BadBazaar. While several vendors have tied BadBazaar to APT15, ESET could not conclusively establish this link. The primary objective of these malware variants is user data exfiltration and espionage. BadBazaar steals device information such as contact lists, call logs, and installed applications, and spies on Signal conversations by secretly attaching the victim’s Signal Plus Messenger app to the attacker’s mobile device. FlyGram can extract sensitive data like contact lists, phone logs, and Google Accounts, along with basic device information. Signal Plus Messenger collects similar data but focuses primarily on tracking the victim's Signal communications. Signal Plus Messenger, once available on Google Play and Samsung Galaxy Store, misuses the link device feature to spy on Signal messages. This allows active espionage on exchanged Signal communication. Despite their harmful nature, these malicious apps were uploaded and disseminated under the guise of legitimate applications. It's important to note that these apps pose a significant risk to users, as they can steal personal information, disrupt operations, or even hold data hostage for ransom.
Description last updated: 2024-05-04T16:37:09.479Z
What's your take? (Question 1 of 5)
Help tune the shared Cybergeist dataset, assist your peers, and earn karma. Expand the panel to get started.
Possible Aliases / Cluster overlaps
It's hard to track cluster overlaps and naming conventions between vendors, so here are some possible overlapping names / profiles you also may want to look at. Create a free account to see the source evidence for each alias, and help fix any errors.
Alias DescriptionVotes
Flygram is a possible alias for Signal Plus Messenger. FlyGram is a malicious software (malware) that first appeared on Google Play in July 2020 and was removed in January 2021. It was designed to exploit and damage users' devices by stealing sensitive data, including basic device information, contact lists, call logs, and Google Account data. The malwa
3
Badbazaar is a possible alias for Signal Plus Messenger. BadBazaar is a malicious software, or malware, employed by EvilBamboo, a threat actor group. This malware is part of three Android spyware families developed by the group, including BADBAZAAR, BADSIGNAL, and BADSOLAR. These are custom-built to target adversaries of the Chinese Communist Party (CCP).
2
Miscellaneous Associations
Other elements of context that could aid in the identification of relevance
Signal
Telegram
Google
Spyware
Malware
Android
Analyst Notes & Discussion
Be the first to leave your mark here! Log in to share your views and vote.
Associated Threat Actors
To see the evidence that has resulted in these threatActor associations, create a free account
Alias DescriptionAssociation TypeVotes
The GREF Threat Actor is associated with Signal Plus Messenger. GREF, a China-aligned Advanced Persistent Threat (APT) group, has been identified as the orchestrator of two active Android malware campaigns. The campaigns have been distributing a malicious software called BadBazaar via two applications, Signal Plus Messenger and FlyGram, through the Google Play sUnspecified
2
The APT15 Threat Actor is associated with Signal Plus Messenger. APT15, also known as Vixen Panda, Nickel, Flea, KE3CHANG, Royal APT, and Playful Dragon, is a threat actor group suspected to be of Chinese origin. The group targets global sectors including trade, economic and financial, energy, and military, aligning with the interests of the Chinese government. IUnspecified
2
Source Document References
Information about the Signal Plus Messenger Malware was read from the documents corpus below. This display is limited to 20 results, create a free account to see more
PreviewSource LinkCreatedAtTitle
ESET
10 months ago
CERT-EU
a year ago
CERT-EU
a year ago
CERT-EU
a year ago
CERT-EU
a year ago
DARKReading
a year ago
CERT-EU
a year ago
CERT-EU
a year ago
Securityaffairs
a year ago
CERT-EU
a year ago
CERT-EU
a year ago
CERT-EU
a year ago
CERT-EU
a year ago
DARKReading
a year ago
CERT-EU
a year ago