888 RAT
Summary
However, soon afterward, the developers of 888 RAT released an expanded Pro version that was capable of infecting Android devices. BladeHawks disguised the 888 RAT and, in small instances, a different malware threat named SpyNote as a legitimate application. As an initial compromise vector, the cybercriminals used dedicated Facebook profiles that lured their victims by posting news in Kurdish about events relevant for the Kurds supporters. Researchers have confirmed that just a couple of bait Facebook posts have managed to register nearly 1,500 downloads of trojanized applications. These include taking arbitrary screenshots, taking photos, sending text messages, making calls, recording the surrounding audio and phone calls conducted on the device, employing phishing techniques to collect the victims Facebook credentials and more.