By using this site, you agree to the Privacy Policy and Terms of Use.
Accept
World of SoftwareWorld of SoftwareWorld of Software
  • News
  • Software
  • Mobile
  • Computing
  • Gaming
  • Videos
  • More
    • Gadget
    • Web Stories
    • Trending
    • Press Release
Search
  • Privacy
  • Terms
  • Advertise
  • Contact
Copyright © All Rights Reserved. World of Software.
Reading: Android Spyware Disguised as Alpine Quest App Targets Russian Military Devices
Share
Sign In
Notification Show More
Font ResizerAa
World of SoftwareWorld of Software
Font ResizerAa
  • Software
  • Mobile
  • Computing
  • Gadget
  • Gaming
  • Videos
Search
  • News
  • Software
  • Mobile
  • Computing
  • Gaming
  • Videos
  • More
    • Gadget
    • Web Stories
    • Trending
    • Press Release
Have an existing account? Sign In
Follow US
  • Privacy
  • Terms
  • Advertise
  • Contact
Copyright © All Rights Reserved. World of Software.
World of Software > Computing > Android Spyware Disguised as Alpine Quest App Targets Russian Military Devices
Computing

Android Spyware Disguised as Alpine Quest App Targets Russian Military Devices

News Room
Last updated: 2025/04/23 at 10:03 AM
News Room Published 23 April 2025
Share
SHARE

Apr 23, 2025Ravie LakshmananSpyware / Mobile Security

Cybersecurity researchers have revealed that Russian military personnel are the target of a new malicious campaign that distributes Android spyware under the guise of the Alpine Quest mapping software.

“The attackers hide this trojan inside modified Alpine Quest mapping software and distribute it in various ways, including through one of the Russian Android app catalogs,” Doctor Web said in an analysis.

The trojan has been found embedded in older versions of the software and propagated as a freely available variant of Alpine Quest Pro, a program with advanced functionality.

The Russian cybersecurity vendor said it also observed the malware, dubbed Android.Spy.1292.origin, being distributed in the form of an APK file via a fake Telegram channel.

Cybersecurity

While the threat actors initially provided a link for downloading the app in one of the Russian app catalogs through the Telegram channel, the trojanized version was later distributed directly as an APK as an app update.

What makes the attack campaign noteworthy is that it takes advantage of the fact that Alpine Quest is used by Russian military personnel in the Special Military Operation zone.

Once installed on an Android device, the malware-laced app looks and functions just like the original, allowing it to stay undetected for extended periods of time, while collecting sensitive data –

  • Mobile phone number and their accounts
  • Contact lists
  • Current date and geolocation
  • Information about stored files, and
  • App version

Besides sending the victim’s location every time it changes to a Telegram bot, the spyware supports the ability to download and run additional modules that allow it to exfiltrate files of interest, particularly those sent via Telegram and WhatsApp.

Android Spyware

“Android.Spy.1292.origin not only allows user locations to be monitored but also confidential files to be hijacked,” Doctor Web said. “In addition, its functionality can be expanded via the download of new modules, which allows it to then execute a wider spectrum of malicious tasks.”

To mitigate the risk posed by such threats, it’s advised to download Android apps only from trusted app marketplaces and avoid downloading “free” paid versions of software from dubious sources.

Russian Organizations Targeted by New Windows Backdoor

The disclosure comes as Kaspersky revealed that various large organizations in Russia, spanning the government, finance, and industrial sectors, have been targeted by a sophisticated backdoor by masquerading it as an update for a secure networking software called ViPNet.

Cybersecurity

“The backdoor targets computers connected to ViPNet networks,” the company said in a preliminary report. “The backdoor was distributed inside LZH archives with a structure typical of updates for the software product in question.”

Present within the archive is a malicious executable (“msinfo32.exe”) that acts as a loader for an encrypted payload also included in the file.

“The loader processes the contents of the file to load the backdoor into memory,” Kaspersky said. This backdoor is versatile: it can connect to a C2 server via TCP, allowing the attacker to steal files from infected computers and launch additional malicious components, among other things.”

Found this article interesting? Follow us on Twitter  and LinkedIn to read more exclusive content we post.

Sign Up For Daily Newsletter

Be keep up! Get the latest breaking news delivered straight to your inbox.
By signing up, you agree to our Terms of Use and acknowledge the data practices in our Privacy Policy. You may unsubscribe at any time.
Share This Article
Facebook Twitter Email Print
Share
What do you think?
Love0
Sad0
Happy0
Sleepy0
Angry0
Dead0
Wink0
Previous Article Roku goes big on new streaming players, TVs and all-new smart projector
Next Article 'Wednesday' Season 2 to Darken Screens This August, New Trailer Reveals
Leave a comment

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Stay Connected

248.1k Like
69.1k Follow
134k Pin
54.3k Follow

Latest News

The Sequel to Nvidia’s Most Popular GPU Hits Shelves Today—With No Reviews
Gadget
Sling Schedule Review: Features, Pricing, Pros & Cons |
Computing
Gemini AI might replace Siri on iPhone, but only for some people
News
Elon Musk’s husband in the treasury still holds his daily job as a software -enceo
News

You Might also Like

Computing

Sling Schedule Review: Features, Pricing, Pros & Cons |

22 Min Read
Computing

The Complete Guide to Crafting Security Headlines That Cut Through the Noise | HackerNoon

7 Min Read
Computing

Ransomware Gangs Use Skitnet Malware for Stealthy Data Theft and Remote Access

5 Min Read
Computing

JD.com to expand full benefits to food delivery riders · TechNode

1 Min Read
//

World of Software is your one-stop website for the latest tech news and updates, follow us now to get the news that matters to you.

Quick Link

  • Privacy Policy
  • Terms of use
  • Advertise
  • Contact

Topics

  • Computing
  • Software
  • Press Release
  • Trending

Sign Up for Our Newsletter

Subscribe to our newsletter to get our newest articles instantly!

World of SoftwareWorld of Software
Follow US
Copyright © All Rights Reserved. World of Software.
Welcome Back!

Sign in to your account

Lost your password?