216.73.216.6

Love? Actually: Fake dating app used as lure in targeted spyware campaign in Pakistan

· Published 28/01/2026 18:26 · Modified 28/01/2026 22:46

Export JSON

Essential information

Published
28/01/2026 18:26
Modified
28/01/2026 22:46
Tags
2026-01-28 android badbazaar clickfix data exfiltration ghostchat pakistan romance scam social engineering spyware whatsapp
Related entities
1 vulnerabilities (cve), 4 observables, 5 techniques (mitre), 2 malware, 4 others

Description

A sophisticated campaign targeting individuals in has been uncovered, using tactics as a lure. The malicious app, named , poses as a chat platform with fake female profiles, requiring hardcoded passcodes to access. Once installed, it enables covert surveillance and . The campaign is part of a broader spy operation, including a attack compromising victims' computers and a device-linking attack gaining access to victims' accounts. These related attacks used websites impersonating Pakistani governmental organizations. The threat actor employs multiple tactics across mobile and desktop platforms, blending , malware delivery, and espionage techniques.

External references