Malware News BusyGasper Malware Packs a Simple but Potent Punch

silversurfer

Level 85
Thread author
Verified
Honorary Member
Top Poster
Content Creator
Malware Hunter
Well-known
Aug 17, 2014
10,210
A small malware campaign is leveraging spyware called BusyGasper, which is highly effective at collecting data on Android phones and exfiltrating it. The malware is unsophisticated, but loaded with 100 uniquely implemented features ranging from device sensor listeners, motion detectors and the ability to process a user’s screen taps.

The mobile malware was identified by researchers at Kaspersky Lab in early 2018 and is believed to have been active since May 2016. The location of the malware author is unknown; however, the FTP server used as the hacker’s command-and-control (C2) is located on the free Russian web hosting service Ucoz. Researchers also made a Russian connection based on victim names (Jana, SlavaAl, Nikusha) found on files recovered by researchers on the FTP server.

“BusyGasper is not all that sophisticated, but demonstrates some unusual features for this type of threat. From a technical point of view, the sample is a unique spy implant with stand-out features… that have been implemented with a degree of originality,” wrote Alexey Firsh, a cyber-threat researcher at Kaspersky Lab, in a technical write-up describing the malware posted on Wednesday.
 

About us

  • MalwareTips is a community-driven platform providing the latest information and resources on malware and cyber threats. Our team of experienced professionals and passionate volunteers work to keep the internet safe and secure. We provide accurate, up-to-date information and strive to build a strong and supportive community dedicated to cybersecurity.

User Menu

Follow us

Follow us on Facebook or Twitter to know first about the latest cybersecurity incidents and malware threats.

Top